← Home

@angular-devkit/build-webpack

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

angulargoogle-wombot

Keywords

Angular CLIAngular DevKitangulardevkitsdk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:css-loader AI (phantom-deps): css-loader is a webpack loader referenced in build config files, not directly imported. Standard pattern for Angular build tooling. ai
phantom-deps phantom-dep:exports-loader AI (phantom-deps): exports-loader is a webpack loader referenced in build config files, not directly imported. Standard pattern for Angular build tooling. ai
phantom-deps phantom-dep:postcss-loader AI (phantom-deps): Optional webpack loader for PostCSS; standard pattern for Angular build tooling. ai
phantom-deps phantom-dep:sass-loader AI (phantom-deps): Optional webpack loader for CSS preprocessing; standard pattern for Angular build tooling. ai
phantom-deps phantom-dep:style-loader AI (phantom-deps): Optional webpack loader; standard pattern for Angular build tooling. ai
phantom-deps phantom-dep:stylus-loader AI (phantom-deps): Optional webpack loader for CSS preprocessing; standard pattern for Angular build tooling. ai
phantom-deps phantom-dep:less AI (phantom-deps): Optional CSS preprocessor dependency; build tools list these for conditional use based on project config, not direct import. ai
phantom-deps phantom-dep:stylus AI (phantom-deps): Optional CSS preprocessor dependency; standard pattern for Angular build tooling. ai
phantom-deps phantom-dep:node-sass AI (phantom-deps): Optional CSS preprocessor dependency; standard pattern for Angular build tooling. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): Utility library referenced in config/build files; phantom detection is a false positive for this build tool package. ai
phantom-deps phantom-dep:request AI (phantom-deps): HTTP utility used conditionally in build tooling; phantom detection is a false positive here. ai
phantom-deps phantom-dep:less-loader AI (phantom-deps): Optional webpack loader for CSS preprocessing; standard pattern for Angular build tooling. ai
semgrep semgrep:child-process-import AI (semgrep): Build tooling legitimately uses child_process to fork webpack/build processes. This is expected behavior for @angular-devkit/build-webpack across all versions. ai
semgrep semgrep:new-function-constructor AI (semgrep): Used as a standard ESM dynamic import() workaround in CJS context within Angular CLI build tooling. Input is a developer-controlled config path, not external user input. Stable pattern across Angular CLI versions. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require() loads developer-specified webpack config files — expected behavior for a build tool. No security risk in this context. ai

Versions (showing 51 of 503)

View all versions
Version Deps Published
0.2102.13 2 / 0
0.2102.12 2 / 0
0.2102.11 2 / 0
0.2102.10 2 / 0
0.2102.9 2 / 0
0.2102.8 2 / 0
0.2102.7 2 / 0
0.2102.6 2 / 0
0.2102.5 2 / 0
0.2102.4 2 / 0
0.2102.3 2 / 0
0.2102.2 2 / 0
0.2102.1 2 / 0
0.2102.0 2 / 0
0.2101.5 2 / 0
0.2101.4 2 / 0
0.2101.3 2 / 0
0.2101.2 2 / 0
0.2101.1 2 / 0
0.2101.0 2 / 0
0.2100.6 2 / 0
0.2100.5 2 / 0
0.2100.4 2 / 0
0.2100.3 2 / 0
0.2100.2 2 / 0
0.2100.1 2 / 0
0.2100.0 2 / 0
0.2003.26 2 / 0
0.2003.25 2 / 0
0.2003.24 2 / 0
0.2003.23 2 / 0
0.2003.22 2 / 0
0.2003.21 2 / 0
0.2003.20 2 / 0
0.2003.19 2 / 0
0.2003.18 2 / 0
0.2003.17 2 / 0
0.2003.16 2 / 0
0.2003.15 2 / 0
0.2003.14 2 / 0
0.2003.13 2 / 0
0.2003.12 2 / 0
0.2003.11 2 / 0
0.2003.10 2 / 0
0.2003.9 2 / 0
0.2003.8 2 / 0
0.2003.7 2 / 0
0.2003.6 2 / 0
0.2003.5 2 / 0
0.2003.4 2 / 0
0.2003.3 2 / 0

v0.2102.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2102.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2102.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2101.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2101.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2101.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2101.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2101.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2101.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2100.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2100.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2100.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2100.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2100.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2100.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2100.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2003.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2003.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2003.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2003.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2003.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2003.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2003.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.