← Home

@salesforce/vscode-services

TypeScript type definitions for Salesforce VS Code Services extension API

6
Versions
BSD-3-Clause
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

ire-npm-team-userjimjagsalesforce-releasesjasonschroeder-sfdcmobifylwc-adminsalesforce-admin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:effect AI (phantom-deps): Type-definitions package; deps declared for consumer use, not directly imported in package source. ai
phantom-deps phantom-dep:jsforce AI (phantom-deps): Type-definitions package; deps declared for consumer use, not directly imported in package source. ai
phantom-deps phantom-dep:vscode-uri AI (phantom-deps): Type-definitions package; deps declared for consumer use, not directly imported in package source. ai
phantom-deps phantom-dep:@types/vscode AI (phantom-deps): Type-definitions package; framework-scoped dep declared for consumers. ai
phantom-deps phantom-dep:@salesforce/core AI (phantom-deps): Same-org type-definitions package; deps declared for consumer use. ai
phantom-deps phantom-dep:@opentelemetry/api AI (phantom-deps): Type-definitions package; OTel deps declared for consumer use. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): Type-definitions package; OTel deps declared for consumer use. ai
phantom-deps phantom-dep:@effect/opentelemetry AI (phantom-deps): Type-definitions package; OTel deps declared for consumer use. ai
phantom-deps phantom-dep:@opentelemetry/sdk-logs AI (phantom-deps): Type-definitions package; OTel deps declared for consumer use. ai
phantom-deps phantom-dep:@opentelemetry/sdk-metrics AI (phantom-deps): Type-definitions package; OTel deps declared for consumer use. ai
phantom-deps phantom-dep:@salesforce/source-tracking AI (phantom-deps): Same-org type-definitions package; deps declared for consumer use. ai
phantom-deps phantom-dep:@opentelemetry/sdk-trace-web AI (phantom-deps): Type-definitions package; OTel deps declared for consumer use. ai
phantom-deps phantom-dep:@opentelemetry/sdk-trace-base AI (phantom-deps): Type-definitions package; OTel deps declared for consumer use. ai
phantom-deps phantom-dep:@opentelemetry/sdk-trace-node AI (phantom-deps): Type-definitions package; OTel deps declared for consumer use. ai
phantom-deps phantom-dep:@salesforce/source-deploy-retrieve AI (phantom-deps): Same-org type-definitions package; deps declared for consumer use. ai
phantom-deps phantom-dep:@azure/monitor-opentelemetry-exporter AI (phantom-deps): Type-definitions package; Azure OTel exporter declared for consumer use, consistent with telemetry purpose. ai
phantom-deps phantom-dep:@opentelemetry/exporter-trace-otlp-http AI (phantom-deps): Type-definitions package; OTel deps declared for consumer use. ai

Versions (showing 6 of 6)

Version Deps Published
66.11.0 17 / 2
66.9.0 17 / 2
66.5.3 17 / 2
66.5.1 17 / 2
65.12.1 17 / 4
65.3.1 17 / 4

v66.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v66.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v66.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v66.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v65.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v65.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.