← Home

ng-packagr

12
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

alan.agius4

Keywords

apfangular-package-formatangularangular-libraryangular-componentscomponent-librarytypescriptcssscss

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:new-function-constructor AI (semgrep): Used solely to wrap dynamic import() for ESM loading in CJS context; input is a module path, not user-controlled arbitrary code. ai
semgrep semgrep:env-spread AI (semgrep): Standard worker-pool env propagation in a build tool; stable pattern across versions. ai
semgrep semgrep:dynamic-require AI (semgrep): Config/plugin loading pattern typical for build tools; stable across versions. ai
email-domain unclaimed-email:spektrakel.de AI (email-domain): Original author email since inception; package published via GH Actions with SLSA provenance, not via email auth. ai

Versions (showing 12 of 12)

Version Deps Published
22.0.1 20 / 0
22.0.0 20 / 0
21.2.5 21 / 0
21.2.3 21 / 0
21.2.2 21 / 0
21.2.1 21 / 0
21.2.0 21 / 0
21.1.0 21 / 0
21.0.1 21 / 0
21.0.0 21 / 0
20.3.2 21 / 0
20.3.1 21 / 0

v22.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.