← Home

ember-source

7
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

real_atekatiegengleref4

Keywords

ember-addon

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/packages/ember-template-compiler/index.js AI (source-diff): Template compiler bundle legitimately combines codegen/exec; canonical Ember dist, stable across releases. ai
dependencies unvetted-dep:@glimmer/manager AI (dependencies): First-party Glimmer dep of Ember; stable across versions. ai
dependencies unvetted-dep:@glimmer/program AI (dependencies): First-party Glimmer dep of Ember; stable across versions. ai
dependencies unvetted-dep:@glimmer/runtime AI (dependencies): First-party Glimmer dep of Ember; stable across versions. ai
dependencies unvetted-dep:@glimmer/opcode-compiler AI (dependencies): First-party Glimmer dep of Ember; stable across versions. ai
phantom-deps phantom-dep:@glimmer/vm AI (phantom-deps): Used via build config, not direct import; expected for this framework. ai
phantom-deps phantom-dep:@glimmer/util AI (phantom-deps): Used via build config, not direct import; expected for this framework. ai
phantom-deps phantom-dep:@glimmer/program AI (phantom-deps): Used via build config, not direct import; expected for this framework. ai
phantom-deps phantom-dep:simple-html-tokenizer AI (phantom-deps): Used via build config, not direct import; expected for this framework. ai
phantom-deps phantom-dep:@glimmer/global-context AI (phantom-deps): Used via build config, not direct import; expected for this framework. ai
phantom-deps phantom-dep:@glimmer/vm-babel-plugins AI (phantom-deps): Used via build config, not direct import; expected for this framework. ai
dependencies unvetted-dep:@glimmer/vm AI (dependencies): First-party Glimmer VM dep of Ember; stable across versions. ai
dependencies unvetted-dep:@glimmer/node AI (dependencies): First-party Glimmer dep of Ember; stable across versions. ai
source-diff large-new-source-files AI (source-diff): Major version restructured dist output; expected for ember-source. ai
source-diff net-exec-file:dist/prod/packages/shared-chunks/compiler-c4yUVrl_.js AI (source-diff): Rollup-bundled Glimmer compiler chunk; heuristic false positive on framework internals. ai
source-diff net-exec-file:dist/dev/packages/shared-chunks/compiler-QUSl_urU.js AI (source-diff): Dev-mode compiler chunk; same false positive as prod variant. ai
phantom-deps phantom-dep:ember-cli-is-package-missing AI (phantom-deps): Config-file reference per Ember CLI conventions; stable false positive. ai
semgrep semgrep:dynamic-require AI (semgrep): Reads project package.json to detect optional-features config; documented Ember addon bootstrap pattern, not a security risk. ai
phantom-deps phantom-dep:ember-cli-babel AI (phantom-deps): Referenced in config files per Ember CLI addon conventions; stable false positive. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped build dependency loaded by convention in Ember CLI pipeline. ai
phantom-deps phantom-dep:@ember/edition-utils AI (phantom-deps): Config-file reference per Ember CLI conventions; stable false positive. ai
phantom-deps phantom-dep:ember-cli-version-checker AI (phantom-deps): Config-file reference per Ember CLI conventions; stable false positive. ai

Versions (showing 7 of 7)

Version Deps Published
7.1.0 18 / 60
7.0.0 18 / 58
6.12.0 24 / 63
6.10.1 40 / 63
6.10.0 40 / 63
6.8.3 40 / 63
6.8.2 40 / 63

v6.10.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.10.0

2 findings
HIGH New file with network + code execution: dist/packages/ember-template-compiler/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.8.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.