@salesforce/pwa-kit-dev
Build tools for pwa-kit
10
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
ire-npm-team-userjimjagsalesforce-releasesjasonschroeder-sfdcmobifylwc-adminsalesforce-admin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:jest-expect-message | AI (phantom-deps): Referenced in jest config by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:source-map-loader | AI (phantom-deps): Referenced in webpack config by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:svg-sprite-loader | AI (phantom-deps): Referenced in webpack config by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-jest | AI (phantom-deps): Referenced in eslint config by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react | AI (phantom-deps): Referenced in eslint config by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:jest-cli | AI (phantom-deps): Dev toolkit ships config files referencing tools by convention; not a real phantom-dep concern. | ai | |
| phantom-deps | phantom-dep:cross-env | AI (phantom-deps): Referenced in build scripts by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/cli | AI (phantom-deps): Framework-scoped babel tooling; loaded by convention in dev toolkit. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped babel tooling; loaded by convention in dev toolkit. | ai | |
| phantom-deps | phantom-dep:@babel/node | AI (phantom-deps): Framework-scoped babel tooling; loaded by convention in dev toolkit. | ai | |
| phantom-deps | phantom-dep:webpack-cli | AI (phantom-deps): Referenced in webpack config files by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:babel-loader | AI (phantom-deps): Referenced in webpack config files by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/parser | AI (phantom-deps): Framework-scoped babel tooling; loaded by convention. | ai | |
| phantom-deps | phantom-dep:ignore-loader | AI (phantom-deps): Referenced in webpack config files by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped babel runtime; loaded by convention. | ai | |
| phantom-deps | phantom-dep:@babel/register | AI (phantom-deps): Framework-scoped babel tooling; loaded by convention. | ai | |
| phantom-deps | phantom-dep:@babel/traverse | AI (phantom-deps): Framework-scoped babel tooling; loaded by convention. | ai | |
| phantom-deps | phantom-dep:jest-fetch-mock | AI (phantom-deps): Referenced in jest config files by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:replace-in-file | AI (phantom-deps): Referenced in config/scripts by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@loadable/server | AI (phantom-deps): Referenced in webpack config by convention; stable false positive. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Build/dev CLI tool legitimately uses child_process to invoke babel/webpack subprocesses. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads project package.json by resolved path — standard webpack plugin pattern. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 usage is in a test file verifying encoding roundtrip, not a payload. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Dev CLI tool passing process.env to child processes is standard and expected behavior. | ai |