← Home

@salesforce/source-deploy-retrieve

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ire-npm-team-userjimjagsalesforce-releasesjasonschroeder-sfdcmobifylwc-adminsalesforce-admin

Keywords

SalesforceSalesforceDXmetadatadeployretrieve

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:lib/src/resolve/adapters/webApplicationsSourceAdapter.js AI (source-diff): Compiled TS with inlined message Map; long lines are build output, not obfuscation. ai
maintainer-change maintainer-added AI (maintainer-change): Large org roster update by trusted salesforce-releases publisher, no other malicious signal. ai
maintainer-change maintainer-removed AI (maintainer-change): Bulk maintainer cleanup consistent with org account hygiene, not takeover. ai
source-diff obfuscated-file:lib/src/registry/levenshtein.js AI (source-diff): TSC-compiled CJS with long inline messages Map; standard build output, not obfuscation. ai
dependencies unvetted-dep:fast-levenshtein AI (dependencies): fast-levenshtein is a well-known string distance library; its use for metadata type suggestion is legitimate and stable for this package. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding is expected behavior for this Salesforce metadata API client — the API returns ZIP files as base64 strings that must be decoded. Not a security concern for this package. ai
phantom-deps phantom-dep:@salesforce/types AI (phantom-deps): First-party Salesforce package in the same org scope; phantom-dep finding is a packaging nuance, not a security risk. ai

Versions (showing 51 of 145)

View all versions
Version Deps Published
12.37.2 14 / 17
12.37.1 14 / 17
12.37.0 14 / 17
12.36.9 14 / 17
12.36.8 14 / 17
12.36.7 14 / 17
12.36.6 14 / 17
12.36.5 14 / 17
12.36.4 14 / 17
12.36.3 14 / 17
12.36.2 14 / 17
12.36.1 14 / 17
12.36.0 14 / 17
12.35.10 14 / 17
12.35.9 14 / 17
12.35.8 14 / 17
12.35.7 14 / 17
12.35.6 14 / 17
12.35.5 14 / 17
12.35.4 14 / 17
12.35.3 14 / 17
12.35.2 14 / 17
12.35.1 14 / 17
12.35.0 14 / 17
12.34.5 14 / 17
12.34.4 14 / 17
12.34.3 14 / 17
12.34.2 14 / 17
12.34.1 14 / 17
12.34.0 14 / 17
12.33.0 14 / 17
12.32.9 14 / 17
12.32.8 14 / 17
12.32.7 14 / 17
12.32.6 14 / 17
12.32.5 14 / 17
12.32.4 14 / 17
12.32.3 14 / 17
12.32.2 14 / 17
12.32.1 14 / 17
12.32.0 14 / 17
12.31.31 14 / 17
12.31.30 14 / 17
12.31.29 14 / 17
12.31.28 14 / 17
12.31.27 14 / 17
12.31.26 14 / 17
12.31.25 14 / 17
12.31.24 14 / 17
12.31.23 14 / 17
12.31.22 14 / 17

v12.37.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.37.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.37.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.36.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.36.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.35.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.35.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.35.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.35.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.35.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.35.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.34.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.33.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.32.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.32.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.32.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.31.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.31.26

2 findings
HIGH New obfuscated file: lib/src/resolve/adapters/webApplicationsSourceAdapter.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.31.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.31.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.31.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.