@wix/ecom
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): Routine autogen SDK aggregator addition from trusted Wix CI publisher. | ai | |
| dependencies | unvetted-dep:@wix/auto_sdk_ecom_draft-subscription-contracts | AI (dependencies): Same-namespace auto-generated Wix SDK module, consistent with existing deps. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Wix org rotates maintainers routinely; published via trusted wix-ci-publisher CI account. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Wix org maintainer rotation; no hostile takeover indicators present. | ai | |
| dependencies | unvetted-dep:@wix/auto_sdk_ecom_wishlists | AI (dependencies): Internal Wix SDK dependency published by the same trusted CI pipeline; consistent with this package's automated release pattern. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Wix mass-produced SDK package; templated naming, no description, and no repo URL are stable traits of this publisher's packages. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Wix CI automated pipeline regularly publishes SDK packages in rapid succession; stable pattern for this publisher. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Wix internal SDK package; missing description is a stable pattern across its many versions. | ai | |
| provenance | no-provenance | AI (provenance): Wix CI publisher consistently publishes without provenance; stable pattern for this package family. | ai |
Versions (showing 51 of 1377)
| Version | Deps | Published |
|---|---|---|
| 1.0.2303 | 59 / 3 | |
| 1.0.2302 | 59 / 3 | |
| 1.0.2300 | 59 / 3 | |
| 1.0.2289 | 59 / 3 | |
| 1.0.2285 | 59 / 3 | |
| 1.0.2276 | 56 / 3 | |
| 1.0.2275 | 56 / 3 | |
| 1.0.2271 | 56 / 3 | |
| 1.0.2266 | 56 / 3 | |
| 1.0.2265 | 56 / 3 | |
| 1.0.2262 | 56 / 3 | |
| 1.0.2261 | 56 / 3 | |
| 1.0.2260 | 56 / 3 | |
| 1.0.2257 | 56 / 3 | |
| 1.0.2254 | 55 / 3 | |
| 1.0.2253 | 55 / 3 | |
| 1.0.2250 | 55 / 3 | |
| 1.0.2247 | 55 / 3 | |
| 1.0.2246 | 55 / 3 | |
| 1.0.2200 | 55 / 3 | |
| 1.0.2199 | 55 / 3 | |
| 1.0.2156 | 55 / 3 | |
| 1.0.2154 | 55 / 3 | |
| 1.0.2153 | 55 / 3 | |
| 1.0.2151 | 55 / 3 | |
| 1.0.2147 | 55 / 3 | |
| 1.0.2114 | 55 / 3 | |
| 1.0.2113 | 55 / 3 | |
| 1.0.2105 | 55 / 3 | |
| 1.0.2104 | 54 / 3 | |
| 1.0.2103 | 54 / 3 | |
| 1.0.2102 | 54 / 3 | |
| 1.0.2101 | 54 / 3 | |
| 1.0.2100 | 54 / 3 | |
| 1.0.2099 | 54 / 3 | |
| 1.0.2098 | 54 / 3 | |
| 1.0.2097 | 54 / 3 | |
| 1.0.2096 | 54 / 3 | |
| 1.0.2095 | 54 / 3 | |
| 1.0.2094 | 54 / 3 | |
| 1.0.2093 | 54 / 3 | |
| 1.0.2092 | 54 / 3 | |
| 1.0.2091 | 54 / 3 | |
| 1.0.2090 | 54 / 3 | |
| 1.0.2089 | 54 / 3 | |
| 1.0.2088 | 54 / 3 | |
| 1.0.2087 | 54 / 3 | |
| 1.0.2086 | 54 / 3 | |
| 1.0.2085 | 54 / 3 | |
| 1.0.2084 | 54 / 3 | |
| 1.0.2083 | 54 / 3 |
v1.0.2303
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2302
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2300
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2289
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2285
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2276
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2275
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2271
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2266
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2265
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2262
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2261
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2260
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2257
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2254
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2253
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2250
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2247
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2246
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.