@salesforce/source-deploy-retrieve
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:lib/src/resolve/adapters/webApplicationsSourceAdapter.js | AI (source-diff): Compiled TS with inlined message Map; long lines are build output, not obfuscation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Large org roster update by trusted salesforce-releases publisher, no other malicious signal. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Bulk maintainer cleanup consistent with org account hygiene, not takeover. | ai | |
| source-diff | obfuscated-file:lib/src/registry/levenshtein.js | AI (source-diff): TSC-compiled CJS with long inline messages Map; standard build output, not obfuscation. | ai | |
| dependencies | unvetted-dep:fast-levenshtein | AI (dependencies): fast-levenshtein is a well-known string distance library; its use for metadata type suggestion is legitimate and stable for this package. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding is expected behavior for this Salesforce metadata API client — the API returns ZIP files as base64 strings that must be decoded. Not a security concern for this package. | ai | |
| phantom-deps | phantom-dep:@salesforce/types | AI (phantom-deps): First-party Salesforce package in the same org scope; phantom-dep finding is a packaging nuance, not a security risk. | ai |
Versions (showing 100 of 145)
| Version | Deps | Published |
|---|---|---|
| 12.37.2 | 14 / 17 | |
| 12.37.1 | 14 / 17 | |
| 12.37.0 | 14 / 17 | |
| 12.36.9 | 14 / 17 | |
| 12.36.8 | 14 / 17 | |
| 12.36.7 | 14 / 17 | |
| 12.36.6 | 14 / 17 | |
| 12.36.5 | 14 / 17 | |
| 12.36.4 | 14 / 17 | |
| 12.36.3 | 14 / 17 | |
| 12.36.2 | 14 / 17 | |
| 12.36.1 | 14 / 17 | |
| 12.36.0 | 14 / 17 | |
| 12.35.10 | 14 / 17 | |
| 12.35.9 | 14 / 17 | |
| 12.35.8 | 14 / 17 | |
| 12.35.7 | 14 / 17 | |
| 12.35.6 | 14 / 17 | |
| 12.35.5 | 14 / 17 | |
| 12.35.4 | 14 / 17 | |
| 12.35.3 | 14 / 17 | |
| 12.35.2 | 14 / 17 | |
| 12.35.1 | 14 / 17 | |
| 12.35.0 | 14 / 17 | |
| 12.34.5 | 14 / 17 | |
| 12.34.4 | 14 / 17 | |
| 12.34.3 | 14 / 17 | |
| 12.34.2 | 14 / 17 | |
| 12.34.1 | 14 / 17 | |
| 12.34.0 | 14 / 17 | |
| 12.33.0 | 14 / 17 | |
| 12.32.9 | 14 / 17 | |
| 12.32.8 | 14 / 17 | |
| 12.32.7 | 14 / 17 | |
| 12.32.6 | 14 / 17 | |
| 12.32.5 | 14 / 17 | |
| 12.32.4 | 14 / 17 | |
| 12.32.3 | 14 / 17 | |
| 12.32.2 | 14 / 17 | |
| 12.32.1 | 14 / 17 | |
| 12.32.0 | 14 / 17 | |
| 12.31.31 | 14 / 17 | |
| 12.31.30 | 14 / 17 | |
| 12.31.29 | 14 / 17 | |
| 12.31.28 | 14 / 17 | |
| 12.31.27 | 14 / 17 | |
| 12.31.26 | 14 / 17 | |
| 12.31.25 | 14 / 17 | |
| 12.31.24 | 14 / 17 | |
| 12.31.23 | 14 / 17 | |
| 12.31.22 | 14 / 17 | |
| 12.31.21 | 14 / 17 | |
| 12.31.20 | 14 / 17 | |
| 12.31.19 | 14 / 17 | |
| 12.31.18 | 14 / 17 | |
| 12.31.17 | 14 / 17 | |
| 12.31.16 | 14 / 17 | |
| 12.31.15 | 14 / 17 | |
| 12.31.14 | 14 / 17 | |
| 12.31.13 | 14 / 17 | |
| 12.31.12 | 14 / 17 | |
| 12.31.11 | 14 / 17 | |
| 12.31.10 | 14 / 17 | |
| 12.31.9 | 14 / 17 | |
| 12.31.8 | 14 / 17 | |
| 12.31.7 | 14 / 17 | |
| 12.31.6 | 14 / 17 | |
| 12.31.5 | 14 / 17 | |
| 12.31.4 | 14 / 17 | |
| 12.31.3 | 14 / 17 | |
| 12.31.2 | 14 / 17 | |
| 12.31.1 | 14 / 17 | |
| 12.31.0 | 14 / 17 | |
| 12.30.2 | 14 / 17 | |
| 12.30.1 | 14 / 17 | |
| 12.30.0 | 14 / 17 | |
| 12.29.1 | 14 / 17 | |
| 12.29.0 | 14 / 17 | |
| 12.28.0 | 14 / 17 | |
| 12.27.2 | 14 / 17 | |
| 12.27.1 | 14 / 17 | |
| 12.27.0 | 14 / 17 | |
| 12.26.1 | 14 / 17 | |
| 12.26.0 | 14 / 17 | |
| 12.25.0 | 14 / 17 | |
| 12.24.3 | 14 / 17 | |
| 12.24.2 | 14 / 17 | |
| 12.24.1 | 14 / 17 | |
| 12.24.0 | 14 / 17 | |
| 12.23.1 | 14 / 17 | |
| 12.23.0 | 14 / 17 | |
| 12.22.14 | 14 / 17 | |
| 12.22.13 | 14 / 17 | |
| 12.22.12 | 14 / 17 | |
| 12.22.11 | 14 / 17 | |
| 12.22.10 | 14 / 17 | |
| 12.22.9 | 14 / 18 | |
| 12.22.8 | 14 / 18 | |
| 12.22.7 | 14 / 18 | |
| 12.22.6 | 14 / 17 |
v12.37.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.37.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.36.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.36.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.35.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.35.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.35.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.35.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.35.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.35.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.34.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.33.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.32.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.32.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.26
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.31.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.31.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.31.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.31.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.30.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.29.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.27.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.25.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.24.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.24.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.24.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.23.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.23.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.22.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.22.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.22.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.22.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.22.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.22.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.22.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v12.22.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.