@strapi/content-type-builder
Create and manage content types
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Large Strapi monorepo; publish cadence varies by plugin; publisher track record is strong. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Size increase attributable to @dnd-kit and zod additions; consistent with documented UI feature work in Strapi monorepo. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Growth driven by legitimate new dependencies (@dnd-kit suite + zod); no obfuscation or injected payloads. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @dnd-kit and zod are well-known, widely-used packages; addition is consistent with UI drag-and-drop feature work. | ai | |
| dependencies | unvetted-dep:@strapi/design-system | AI (dependencies): @strapi/design-system is an official first-party Strapi package; unvetted status is a registry artifact, not a security concern for this package. | ai | |
| dependencies | unvetted-dep:@strapi/icons | AI (dependencies): @strapi/icons is an official first-party Strapi design system package; unvetted status is a registry artifact, not a security concern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo package from official Strapi org; short README and no keywords are expected for internal plugin packages that rely on main project docs. | ai | |
| license | uncommon-license:SEE LICENSE IN LICENSE | AI (license): Standard Strapi license declaration pattern used across all their packages; refers to the LICENSE file in the package. | ai | |
| provenance | no-provenance | AI (provenance): Strapi packages historically published without Sigstore provenance; no security concern given the established publisher identity. | ai |
Versions (showing 51 of 68)
| Version | Deps | Published |
|---|---|---|
| 5.51.0 | 26 / 22 | |
| 5.50.2 | 26 / 22 | |
| 5.50.1 | 26 / 17 | |
| 5.50.0 | 26 / 17 | |
| 5.49.0 | 26 / 15 | |
| 5.48.1 | 26 / 15 | |
| 5.48.0 | 26 / 15 | |
| 5.47.1 | 26 / 15 | |
| 5.47.0 | 26 / 15 | |
| 5.46.1 | 26 / 15 | |
| 5.46.0 | 26 / 15 | |
| 5.45.1 | 26 / 15 | |
| 5.45.0 | 26 / 15 | |
| 5.44.0 | 26 / 15 | |
| 5.43.0 | 26 / 15 | |
| 5.42.1 | 26 / 15 | |
| 5.42.0 | 26 / 15 | |
| 5.41.1 | 26 / 15 | |
| 5.41.0 | 26 / 15 | |
| 5.40.0 | 26 / 15 | |
| 5.39.0 | 26 / 15 | |
| 5.38.1 | 26 / 15 | |
| 5.38.0 | 26 / 15 | |
| 5.37.1 | 26 / 15 | |
| 5.37.0 | 26 / 15 | |
| 5.36.1 | 26 / 15 | |
| 5.36.0 | 26 / 15 | |
| 5.35.0 | 26 / 15 | |
| 5.34.0 | 26 / 15 | |
| 5.33.4 | 26 / 15 | |
| 5.33.3 | 26 / 15 | |
| 5.33.2 | 26 / 15 | |
| 5.31.3 | 26 / 15 | |
| 5.31.2 | 26 / 15 | |
| 5.31.1 | 26 / 15 | |
| 5.31.0 | 26 / 15 | |
| 5.30.1 | 26 / 15 | |
| 5.30.0 | 26 / 15 | |
| 5.29.0 | 26 / 15 | |
| 5.28.0 | 26 / 15 | |
| 5.27.0 | 26 / 15 | |
| 5.26.0 | 26 / 15 | |
| 5.25.0 | 20 / 14 | |
| 5.24.2 | 20 / 14 | |
| 5.24.1 | 20 / 14 | |
| 5.24.0 | 20 / 14 | |
| 5.23.6 | 20 / 14 | |
| 5.23.5 | 20 / 14 | |
| 5.23.4 | 20 / 14 | |
| 5.23.3 | 20 / 14 | |
| 5.23.2 | 20 / 14 |
v5.51.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.50.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.50.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.50.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.