@strapi/core
Core of Strapi
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:copyfiles | AI (phantom-deps): Copyfiles is a build tool declared in dependencies and used in build scripts; phantom-dep pattern is expected for CLI/build tooling. | ai | |
| provenance | no-provenance | AI (provenance): Lack of provenance is common (88% of npm); not a disqualifier for established packages from trusted publishers. | ai | |
| phantom-deps | phantom-dep:@strapi/generators | AI (phantom-deps): Same-org @strapi/* package; used indirectly via CLI or dynamic imports in the Strapi monorepo. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Large monorepo packages commonly declare CLI/build deps that are used indirectly or in tooling scripts. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): TypeScript is used as a build-time dependency in Strapi's monorepo; phantom detection is expected. | ai | |
| dependencies | unvetted-dep:koa-ip | AI (dependencies): koa-ip is a standard Koa middleware for IP filtering; appropriate dependency for a web framework core. | ai | |
| dependencies | unvetted-dep:@koa/cors | AI (dependencies): @koa/cors is the official CORS middleware for Koa, maintained by the Koa org; appropriate for a web framework. | ai | |
| dependencies | unvetted-dep:koa-helmet | AI (dependencies): koa-helmet is a well-known security middleware for Koa; appropriate for a web framework core. | ai | |
| dependencies | unvetted-dep:koa-session | AI (dependencies): koa-session is a standard session middleware for Koa; appropriate for a web framework core. | ai | |
| dependencies | unvetted-dep:@vercel/stega | AI (dependencies): @vercel/stega is a known Vercel utility for steganographic encoding; legitimate dependency for Strapi's draft/preview features. | ai | |
| phantom-deps | phantom-dep:ora | AI (phantom-deps): Large monorepo packages commonly declare CLI/build deps that are used indirectly or in tooling scripts. | ai | |
| phantom-deps | phantom-dep:execa | AI (phantom-deps): Large monorepo packages commonly declare CLI/build deps that are used indirectly or in tooling scripts. | ai | |
| phantom-deps | phantom-dep:pkg-up | AI (phantom-deps): Large monorepo packages commonly declare CLI/build deps that are used indirectly or in tooling scripts. | ai | |
| phantom-deps | phantom-dep:inquirer | AI (phantom-deps): Large monorepo packages commonly declare CLI/build deps that are used indirectly or in tooling scripts. | ai | |
| bogus-package | bogus-package | AI (bogus-package): @strapi/core is the core of the well-known Strapi headless CMS. Short README and no keywords are cosmetic issues, not spam indicators. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @strapi/core is the legitimate Strapi framework core package, not a typosquat of 'cors'. The Levenshtein match is coincidental; the packages are entirely unrelated. | ai |
Versions (showing 51 of 59)
| Version | Deps | Published |
|---|---|---|
| 5.51.0 | 58 / 23 | |
| 5.50.2 | 58 / 23 | |
| 5.50.1 | 58 / 22 | |
| 5.50.0 | 58 / 22 | |
| 5.49.0 | 59 / 24 | |
| 5.48.1 | 59 / 24 | |
| 5.48.0 | 58 / 24 | |
| 5.47.1 | 57 / 24 | |
| 5.47.0 | 57 / 25 | |
| 5.46.1 | 55 / 25 | |
| 5.46.0 | 55 / 25 | |
| 5.45.1 | 55 / 25 | |
| 5.45.0 | 55 / 25 | |
| 5.44.0 | 55 / 25 | |
| 5.43.0 | 55 / 25 | |
| 5.42.1 | 55 / 25 | |
| 5.42.0 | 55 / 25 | |
| 5.41.1 | 55 / 25 | |
| 5.41.0 | 55 / 25 | |
| 5.40.0 | 56 / 25 | |
| 5.39.0 | 56 / 25 | |
| 5.38.1 | 56 / 25 | |
| 5.38.0 | 56 / 25 | |
| 5.37.1 | 56 / 25 | |
| 5.37.0 | 56 / 25 | |
| 5.36.1 | 56 / 25 | |
| 5.36.0 | 56 / 23 | |
| 5.35.0 | 56 / 23 | |
| 5.34.0 | 56 / 23 | |
| 5.33.4 | 56 / 23 | |
| 5.33.3 | 56 / 23 | |
| 5.33.2 | 56 / 23 | |
| 5.33.1 | 56 / 23 | |
| 5.33.0 | 56 / 23 | |
| 5.32.0 | 56 / 23 | |
| 5.31.3 | 56 / 23 | |
| 5.31.2 | 56 / 23 | |
| 5.31.1 | 56 / 23 | |
| 5.31.0 | 56 / 23 | |
| 5.30.1 | 56 / 23 | |
| 5.30.0 | 56 / 23 | |
| 5.29.0 | 56 / 23 | |
| 5.28.0 | 56 / 23 | |
| 5.27.0 | 56 / 23 | |
| 5.26.0 | 56 / 23 | |
| 5.25.0 | 56 / 23 | |
| 5.24.2 | 56 / 23 | |
| 5.24.1 | 56 / 23 | |
| 5.24.0 | 56 / 23 | |
| 5.23.6 | 55 / 23 | |
| 5.23.5 | 55 / 23 |
v5.51.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.50.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.50.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.50.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.46.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.45.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.45.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.44.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.43.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.42.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.42.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.41.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.40.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.39.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.38.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.38.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.37.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.33.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.33.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.33.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.33.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.33.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.32.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bassel17) than the most recent previously approved version (alexandrebodin) on 2025-12-11, but bassel17 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v5.31.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.31.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.31.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.31.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.30.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.27.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.24.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.24.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.24.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.23.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.23.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.