← Home

contentful-management

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

contentful-ecosystem

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:postinstall AI (install-scripts): postinstall runs patch-package, a standard dev tool for patching dependencies. This is a legitimate, well-known pattern used by the official Contentful SDK and poses no security risk. ai
phantom-deps phantom-dep:@types/json-patch AI (phantom-deps): @types/json-patch is a TypeScript type declaration package; it's normal to declare it as a dependency without direct imports since types are consumed at compile time. ai
phantom-deps phantom-dep:lodash.isplainobject AI (phantom-deps): lodash.isplainobject is a well-known utility bundled via webpack; phantom-dep finding is a stable false positive for this package. ai
provenance publisher-changed AI (provenance): Package migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation; publisher change from contentful-ecosystem to GitHub Actions is the expected outcome of this legitimate automation migration. ai
provenance no-provenance AI (provenance): Established Contentful SDK package with 732 versions; lack of Sigstore provenance is common and not a risk signal for this well-known publisher. ai
dependencies unvetted-dep:contentful-sdk-core AI (dependencies): contentful-sdk-core is a first-party Contentful package; expected dependency for this SDK across all versions. ai
dependencies unvetted-dep:@contentful/rich-text-types AI (dependencies): @contentful/rich-text-types is a first-party Contentful package; expected dependency for this SDK across all versions. ai
phantom-deps phantom-dep:process AI (phantom-deps): process is a Node.js polyfill for browser bundle compatibility via rollup-plugin-polyfill-node; standard pattern for isomorphic SDKs. ai
phantom-deps phantom-dep:globals AI (phantom-deps): globals is used as a browser polyfill in the rollup bundle for this isomorphic SDK; not directly imported in source but legitimately declared as a runtime dep. ai

Versions (showing 51 of 198)

View all versions
Version Deps Published
12.10.0 6 / 38
12.9.0 6 / 38
12.8.0 6 / 38
12.7.0 6 / 38
12.6.0 6 / 38
12.5.1 6 / 38
12.5.0 6 / 38
12.4.0 6 / 38
12.3.3 6 / 38
12.3.2 6 / 38
12.3.1 6 / 38
12.3.0 6 / 38
12.2.0 6 / 38
12.1.0 6 / 38
12.0.0 6 / 38
11.76.0 5 / 47
11.75.0 5 / 47
11.74.0 5 / 47
11.73.1 5 / 47
11.73.0 5 / 47
11.72.2 5 / 47
11.72.1 5 / 47
11.72.0 5 / 47
11.71.0 5 / 47
11.70.0 5 / 47
11.69.3 5 / 47
11.69.2 5 / 47
11.69.1 5 / 47
11.69.0 5 / 47
11.68.1 5 / 47
11.68.0 5 / 47
11.67.2 5 / 47
11.67.1 5 / 47
11.67.0 5 / 47
11.66.0 5 / 47
11.65.0 5 / 47
11.64.0 5 / 47
11.63.1 5 / 47
11.63.0 5 / 47
11.62.1 5 / 47
11.62.0 5 / 47
11.61.1 5 / 47
11.61.0 5 / 47
11.60.4 5 / 47
11.60.3 5 / 47
11.60.2 5 / 47
11.60.1 5 / 47
11.60.0 5 / 47
11.59.0 5 / 47
11.58.1 5 / 47
11.58.0 5 / 47

v12.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.