@wix/crm
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Auto-generated Wix SDK packages consistently lack descriptions and repo URLs; this is a known pattern for this publisher. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Wix auto-generated SDK packages routinely omit descriptions; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@wix/auto_sdk_crm_notes | AI (dependencies): Internal Wix sub-package from a trusted publisher with 1583 approved packages. | ai | |
| dependencies | unvetted-dep:@wix/auto_sdk_crm_tasks | AI (dependencies): Internal Wix sub-package from a trusted publisher with 1583 approved packages. | ai | |
| dependencies | unvetted-dep:@wix/crm_app-extensions | AI (dependencies): Internal Wix sub-package from a trusted publisher with 1583 approved packages. | ai | |
| dependencies | unvetted-dep:@wix/auto_sdk_crm_labels | AI (dependencies): Internal Wix sub-package from a trusted publisher with 1583 approved packages. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @wix/crm is a legitimate Wix CRM SDK, not a typosquat of 'cors'; the levenshtein match is a false positive. | ai | |
| dependencies | unvetted-dep:@wix/auto_sdk_crm_attachments | AI (dependencies): Internal Wix sub-package from a trusted publisher with 1583 approved packages. | ai | |
| dependencies | unvetted-dep:@wix/auto_sdk_crm_extended-fields | AI (dependencies): Internal Wix sub-package from a trusted publisher with 1583 approved packages. | ai | |
| dependencies | unvetted-dep:@wix/auto_sdk_crm_submitted-contact | AI (dependencies): Internal Wix sub-package from a trusted publisher with 1583 approved packages. | ai | |
| dependencies | unvetted-dep:@wix/auto_sdk_crm_pipelines | AI (dependencies): Internal Wix sub-package from a trusted publisher with 1583 approved packages. | ai | |
| dependencies | unvetted-dep:@wix/auto_sdk_crm_cards | AI (dependencies): Internal Wix sub-package from a trusted publisher with 1583 approved packages. | ai |
Versions (showing 51 of 880)
| Version | Deps | Published |
|---|---|---|
| 1.0.1543 | 10 / 2 | |
| 1.0.1542 | 10 / 2 | |
| 1.0.1541 | 10 / 2 | |
| 1.0.1540 | 10 / 2 | |
| 1.0.1539 | 10 / 2 | |
| 1.0.1538 | 10 / 2 | |
| 1.0.1537 | 10 / 2 | |
| 1.0.1536 | 10 / 2 | |
| 1.0.1535 | 10 / 2 | |
| 1.0.1534 | 10 / 2 | |
| 1.0.1533 | 10 / 2 | |
| 1.0.1532 | 10 / 2 | |
| 1.0.1531 | 10 / 2 | |
| 1.0.1530 | 10 / 2 | |
| 1.0.1529 | 10 / 2 | |
| 1.0.1528 | 10 / 2 | |
| 1.0.1527 | 10 / 2 | |
| 1.0.1526 | 10 / 2 | |
| 1.0.1496 | 8 / 2 | |
| 1.0.1489 | 8 / 2 | |
| 1.0.1440 | 8 / 2 | |
| 1.0.1376 | 8 / 2 | |
| 1.0.1324 | 8 / 2 | |
| 1.0.1323 | 8 / 2 | |
| 1.0.1322 | 8 / 2 | |
| 1.0.1321 | 8 / 2 | |
| 1.0.1320 | 8 / 2 | |
| 1.0.1319 | 8 / 2 | |
| 1.0.1318 | 8 / 2 | |
| 1.0.1317 | 8 / 2 | |
| 1.0.1316 | 8 / 2 | |
| 1.0.1315 | 8 / 2 | |
| 1.0.1314 | 8 / 2 | |
| 1.0.1313 | 8 / 2 | |
| 1.0.1312 | 8 / 2 | |
| 1.0.1311 | 8 / 2 | |
| 1.0.1310 | 8 / 2 | |
| 1.0.1309 | 8 / 2 | |
| 1.0.1308 | 8 / 2 | |
| 1.0.1307 | 8 / 2 | |
| 1.0.1306 | 8 / 2 | |
| 1.0.1305 | 8 / 2 | |
| 1.0.1304 | 8 / 2 | |
| 1.0.1303 | 8 / 2 | |
| 1.0.1302 | 8 / 2 | |
| 1.0.1301 | 8 / 2 | |
| 1.0.1300 | 8 / 2 | |
| 1.0.1299 | 8 / 2 | |
| 1.0.1298 | 8 / 2 | |
| 1.0.1297 | 8 / 2 | |
| 1.0.1296 | 8 / 2 |
v1.0.1543
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1542
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1541
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1540
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1539
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1538
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1537
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1536
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1535
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1534
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1533
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1532
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1531
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1530
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1529
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1528
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1527
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1496
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1489
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1440
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1376
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1324
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1323
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1322
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1321
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1320
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1319
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1318
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1317
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1316
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1315
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1314
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1313
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1312
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1311
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1310
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1309
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1308
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1307
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1306
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1305
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1304
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1303
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1302
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1301
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1300
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1299
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1298
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1297
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1296
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.