ember-source
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/packages/ember-template-compiler/index.js | AI (source-diff): Template compiler bundle legitimately combines codegen/exec; canonical Ember dist, stable across releases. | ai | |
| dependencies | unvetted-dep:@glimmer/manager | AI (dependencies): First-party Glimmer dep of Ember; stable across versions. | ai | |
| dependencies | unvetted-dep:@glimmer/program | AI (dependencies): First-party Glimmer dep of Ember; stable across versions. | ai | |
| dependencies | unvetted-dep:@glimmer/runtime | AI (dependencies): First-party Glimmer dep of Ember; stable across versions. | ai | |
| dependencies | unvetted-dep:@glimmer/opcode-compiler | AI (dependencies): First-party Glimmer dep of Ember; stable across versions. | ai | |
| phantom-deps | phantom-dep:@glimmer/vm | AI (phantom-deps): Used via build config, not direct import; expected for this framework. | ai | |
| phantom-deps | phantom-dep:@glimmer/util | AI (phantom-deps): Used via build config, not direct import; expected for this framework. | ai | |
| phantom-deps | phantom-dep:@glimmer/program | AI (phantom-deps): Used via build config, not direct import; expected for this framework. | ai | |
| phantom-deps | phantom-dep:simple-html-tokenizer | AI (phantom-deps): Used via build config, not direct import; expected for this framework. | ai | |
| phantom-deps | phantom-dep:@glimmer/global-context | AI (phantom-deps): Used via build config, not direct import; expected for this framework. | ai | |
| phantom-deps | phantom-dep:@glimmer/vm-babel-plugins | AI (phantom-deps): Used via build config, not direct import; expected for this framework. | ai | |
| dependencies | unvetted-dep:@glimmer/vm | AI (dependencies): First-party Glimmer VM dep of Ember; stable across versions. | ai | |
| dependencies | unvetted-dep:@glimmer/node | AI (dependencies): First-party Glimmer dep of Ember; stable across versions. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Major version restructured dist output; expected for ember-source. | ai | |
| source-diff | net-exec-file:dist/prod/packages/shared-chunks/compiler-c4yUVrl_.js | AI (source-diff): Rollup-bundled Glimmer compiler chunk; heuristic false positive on framework internals. | ai | |
| source-diff | net-exec-file:dist/dev/packages/shared-chunks/compiler-QUSl_urU.js | AI (source-diff): Dev-mode compiler chunk; same false positive as prod variant. | ai | |
| phantom-deps | phantom-dep:ember-cli-is-package-missing | AI (phantom-deps): Config-file reference per Ember CLI conventions; stable false positive. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Reads project package.json to detect optional-features config; documented Ember addon bootstrap pattern, not a security risk. | ai | |
| phantom-deps | phantom-dep:ember-cli-babel | AI (phantom-deps): Referenced in config files per Ember CLI addon conventions; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped build dependency loaded by convention in Ember CLI pipeline. | ai | |
| phantom-deps | phantom-dep:@ember/edition-utils | AI (phantom-deps): Config-file reference per Ember CLI conventions; stable false positive. | ai | |
| phantom-deps | phantom-dep:ember-cli-version-checker | AI (phantom-deps): Config-file reference per Ember CLI conventions; stable false positive. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 7.1.0 | 18 / 60 | |
| 7.0.0 | 18 / 58 | |
| 6.12.0 | 24 / 63 | |
| 6.10.1 | 40 / 63 | |
| 6.10.0 | 40 / 63 | |
| 6.8.3 | 40 / 63 | |
| 6.8.2 | 40 / 63 |
v6.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.10.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.8.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.8.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.