workbox-webpack-plugin
A plugin for your Webpack build process, helping you generate a manifest of local files that workbox-sw should precache.
28
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
gauntfacejeffposnickaddyosmaniphilipwaltontropicadriwestonrutertomayackhempeniusswissspidy
Keywords
workboxworkboxjswebpackservice workercachingfetch requestsofflinefile manifest
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:fast-json-stable-stringify | AI (dependencies): fast-json-stable-stringify is a stable, widely-used utility; its use in a webpack plugin is legitimate. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): pretty-bytes is a legitimate utility for byte formatting; reasonable addition for a webpack plugin. | ai | |
| provenance | no-provenance | AI (provenance): Established Google-maintained package published well before Sigstore provenance was widely adopted; absence of provenance is expected and not a risk signal here. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): @babel/runtime is a declared dependency in package.json and is a standard Babel convention-loaded runtime helper; not a real phantom dep for this package. | ai | |
| provenance | publisher-changed | AI (provenance): tropicadri is a known Google engineer on the Workbox team; this is a documented team transition from jeffposnick, not a compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): snugug is a known Workbox contributor; addition reflects legitimate team expansion in official project. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Long gap reflects major version release cycle (v5→v6); publisher has strong track record with no compromise signals. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 7.4.1 | 5 / 2 | |
| 7.4.0 | 5 / 2 | |
| 7.3.0 | 5 / 2 | |
| 7.1.0 | 5 / 2 | |
| 7.0.0 | 5 / 2 | |
| 6.6.1 | 5 / 2 | |
| 6.6.0 | 5 / 2 | |
| 6.5.4 | 5 / 1 | |
| 6.5.3 | 5 / 1 | |
| 6.5.2 | 5 / 1 | |
| 6.5.1 | 5 / 1 | |
| 6.5.0 | 5 / 1 | |
| 6.4.2 | 6 / 0 | |
| 6.4.1 | 6 / 0 | |
| 6.4.0 | 6 / 0 | |
| 6.3.0 | 6 / 0 | |
| 6.2.4 | 6 / 0 | |
| 6.2.3 | 6 / 0 | |
| 6.2.2 | 6 / 0 | |
| 6.2.1 | 6 / 0 | |
| 6.2.0 | 6 / 0 | |
| 6.1.5 | 6 / 0 | |
| 6.1.2 | 6 / 0 | |
| 6.1.1 | 6 / 0 | |
| 6.1.0 | 6 / 0 | |
| 6.0.2 | 6 / 0 | |
| 6.0.0 | 6 / 0 | |
| 5.1.4 | 6 / 0 |
v6.5.4
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.