@stripe/extensibility-dev-tools
Development toolkit for Stripe Apps. Provides template generation, manifest parsing, workspace management, schema handling, and CLI tools.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Stripe org account rotation (cttsai → cttsai-stripe); consistent with internal identity management, not a hostile takeover. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of yuluomeng/cttsai mirrors addition of cttsai-stripe; internal Stripe account rename pattern. | ai | |
| dependencies | unvetted-dep:@formspec/core | AI (dependencies): Stripe-internal alpha package; expected dependency for this dev-tools package. | ai | |
| dependencies | unvetted-dep:@formspec/build | AI (dependencies): Stripe-internal alpha package; expected dependency for this dev-tools package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Internal Stripe dev tooling; missing description is expected for private/internal packages. | ai | |
| provenance | no-provenance | AI (provenance): Low-traffic internal tooling; absence of provenance is not a meaningful risk signal here. | ai | |
| phantom-deps | phantom-dep:mustache | AI (phantom-deps): Declared in config but not directly imported; stable false positive for this tooling package. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 1.0.4 | 13 / 8 | |
| 0.25.1 | 13 / 8 | |
| 0.24.3 | 13 / 8 | |
| 0.24.2 | 13 / 8 | |
| 0.23.7 | 13 / 8 | |
| 0.23.5 | 13 / 8 |
v1.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.23.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.