← Home

@shoplflow/base

6
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

jason-jeongdaisy.kimshoplworks-devkim-777kevin.jeon

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher is confirmed by SLSA provenance attestation; stable CI/CD pattern for this package. ai
dependencies unvetted-dep:@figma/code-connect AI (dependencies): Official Figma tooling package matching the figma:parse/publish scripts added in this version. ai
phantom-deps phantom-dep:@figma/code-connect AI (phantom-deps): @figma/code-connect is used via CLI (npx figma connect) in scripts, not direct import; phantom-dep is a stable false positive here. ai

Versions (showing 6 of 107)

Version Deps Published
0.38.1 13 / 41
0.38.0 13 / 41
0.37.6 13 / 41
0.37.5 13 / 41
0.37.4 13 / 41
0.37.3 13 / 41

v0.38.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.38.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.