@salesforce/ui-bundle-template-base-sfdx-project
Base SFDX project template
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-spread | AI (semgrep): Standard child-process env forwarding pattern in a Salesforce tooling script; not exfiltration. | ai |
Versions (showing 51 of 251)
| Version | Deps | Published |
|---|---|---|
| 2.1.0 | 0 / 13 | |
| 2.0.0 | 0 / 13 | |
| 1.135.0 | 0 / 13 | |
| 1.134.5 | 0 / 13 | |
| 1.134.4 | 0 / 13 | |
| 1.134.3 | 0 / 13 | |
| 1.134.2 | 0 / 13 | |
| 1.134.1 | 0 / 13 | |
| 1.134.0 | 0 / 13 | |
| 1.133.2 | 0 / 13 | |
| 1.133.1 | 0 / 13 | |
| 1.133.0 | 0 / 13 | |
| 1.132.0 | 0 / 13 | |
| 1.131.3 | 0 / 13 | |
| 1.131.2 | 0 / 13 | |
| 1.131.0 | 0 / 13 | |
| 1.130.2 | 0 / 13 | |
| 1.130.1 | 0 / 13 | |
| 1.130.0 | 0 / 13 | |
| 1.129.1 | 0 / 13 | |
| 1.129.0 | 0 / 13 | |
| 1.128.0 | 0 / 13 | |
| 1.127.0 | 0 / 13 | |
| 1.123.0 | 0 / 13 | |
| 1.122.2 | 0 / 13 | |
| 1.122.1 | 0 / 13 | |
| 1.122.0 | 0 / 13 | |
| 1.121.0 | 0 / 13 | |
| 1.120.7 | 0 / 13 | |
| 1.120.6 | 0 / 13 | |
| 1.120.4 | 0 / 13 | |
| 1.120.3 | 0 / 13 | |
| 1.120.2 | 0 / 13 | |
| 1.120.1 | 0 / 13 | |
| 1.120.0 | 0 / 13 | |
| 1.119.6 | 0 / 13 | |
| 1.119.5 | 0 / 13 | |
| 1.119.4 | 0 / 13 | |
| 1.119.3 | 0 / 13 | |
| 1.119.2 | 0 / 13 | |
| 1.119.1 | 0 / 13 | |
| 1.119.0 | 0 / 13 | |
| 1.118.4 | 0 / 13 | |
| 1.118.3 | 0 / 13 | |
| 1.118.2 | 0 / 13 | |
| 1.118.1 | 0 / 13 | |
| 1.118.0 | 0 / 13 | |
| 1.117.5 | 0 / 13 | |
| 1.117.4 | 0 / 13 | |
| 1.117.3 | 0 / 13 | |
| 1.117.2 | 0 / 13 |
v1.123.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.122.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.122.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.122.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.121.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.120.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.120.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.