@angular-devkit/build-webpack
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:css-loader | AI (phantom-deps): css-loader is a webpack loader referenced in build config files, not directly imported. Standard pattern for Angular build tooling. | ai | |
| phantom-deps | phantom-dep:exports-loader | AI (phantom-deps): exports-loader is a webpack loader referenced in build config files, not directly imported. Standard pattern for Angular build tooling. | ai | |
| phantom-deps | phantom-dep:postcss-loader | AI (phantom-deps): Optional webpack loader for PostCSS; standard pattern for Angular build tooling. | ai | |
| phantom-deps | phantom-dep:sass-loader | AI (phantom-deps): Optional webpack loader for CSS preprocessing; standard pattern for Angular build tooling. | ai | |
| phantom-deps | phantom-dep:style-loader | AI (phantom-deps): Optional webpack loader; standard pattern for Angular build tooling. | ai | |
| phantom-deps | phantom-dep:stylus-loader | AI (phantom-deps): Optional webpack loader for CSS preprocessing; standard pattern for Angular build tooling. | ai | |
| phantom-deps | phantom-dep:less | AI (phantom-deps): Optional CSS preprocessor dependency; build tools list these for conditional use based on project config, not direct import. | ai | |
| phantom-deps | phantom-dep:stylus | AI (phantom-deps): Optional CSS preprocessor dependency; standard pattern for Angular build tooling. | ai | |
| phantom-deps | phantom-dep:node-sass | AI (phantom-deps): Optional CSS preprocessor dependency; standard pattern for Angular build tooling. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Utility library referenced in config/build files; phantom detection is a false positive for this build tool package. | ai | |
| phantom-deps | phantom-dep:request | AI (phantom-deps): HTTP utility used conditionally in build tooling; phantom detection is a false positive here. | ai | |
| phantom-deps | phantom-dep:less-loader | AI (phantom-deps): Optional webpack loader for CSS preprocessing; standard pattern for Angular build tooling. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Build tooling legitimately uses child_process to fork webpack/build processes. This is expected behavior for @angular-devkit/build-webpack across all versions. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Used as a standard ESM dynamic import() workaround in CJS context within Angular CLI build tooling. Input is a developer-controlled config path, not external user input. Stable pattern across Angular CLI versions. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require() loads developer-specified webpack config files — expected behavior for a build tool. No security risk in this context. | ai |
Versions (showing 100 of 503)
| Version | Deps | Published |
|---|---|---|
| 0.901.2 | 3 / 0 | |
| 0.901.1 | 3 / 0 | |
| 0.901.0 | 3 / 0 | |
| 0.900.7 | 3 / 0 | |
| 0.900.6 | 3 / 0 | |
| 0.900.5 | 3 / 0 | |
| 0.900.4 | 3 / 0 | |
| 0.900.3 | 3 / 0 | |
| 0.900.2 | 3 / 0 | |
| 0.900.1 | 3 / 0 | |
| 0.900.0 | 3 / 0 | |
| 0.803.29 | 3 / 0 | |
| 0.803.28 | 3 / 0 | |
| 0.803.27 | 3 / 0 | |
| 0.803.26 | 3 / 0 | |
| 0.803.25 | 3 / 0 | |
| 0.803.24 | 3 / 0 | |
| 0.803.23 | 3 / 0 | |
| 0.803.22 | 3 / 0 | |
| 0.803.21 | 3 / 0 | |
| 0.803.20 | 3 / 0 | |
| 0.803.19 | 3 / 0 | |
| 0.803.18 | 3 / 0 | |
| 0.803.17 | 3 / 0 | |
| 0.803.16 | 3 / 0 | |
| 0.803.15 | 3 / 0 | |
| 0.803.14 | 3 / 0 | |
| 0.803.13 | 3 / 0 | |
| 0.803.12 | 3 / 0 | |
| 0.803.10 | 3 / 0 | |
| 0.803.9 | 4 / 0 | |
| 0.803.8 | 4 / 0 | |
| 0.803.7 | 4 / 0 | |
| 0.803.6 | 4 / 0 | |
| 0.803.5 | 4 / 0 | |
| 0.803.4 | 4 / 0 | |
| 0.803.3 | 4 / 0 | |
| 0.803.2 | 4 / 0 | |
| 0.803.1 | 4 / 0 | |
| 0.803.0 | 4 / 0 | |
| 0.802.2 | 4 / 0 | |
| 0.802.1 | 4 / 0 | |
| 0.802.0 | 4 / 0 | |
| 0.801.3 | 4 / 0 | |
| 0.801.2 | 4 / 0 | |
| 0.801.1 | 4 / 0 | |
| 0.801.0 | 4 / 0 | |
| 0.800.6 | 4 / 0 | |
| 0.800.5 | 4 / 0 | |
| 0.800.4 | 4 / 0 | |
| 0.800.3 | 4 / 0 | |
| 0.800.2 | 4 / 0 | |
| 0.800.1 | 4 / 0 | |
| 0.800.0 | 4 / 0 | |
| 0.13.10 | 3 / 0 | |
| 0.13.9 | 3 / 0 | |
| 0.13.8 | 3 / 0 | |
| 0.13.7 | 3 / 0 | |
| 0.13.6 | 3 / 0 | |
| 0.13.5 | 3 / 0 | |
| 0.13.4 | 3 / 0 | |
| 0.13.3 | 3 / 0 | |
| 0.13.2 | 3 / 0 | |
| 0.13.1 | 3 / 0 | |
| 0.13.0 | 3 / 0 | |
| 0.12.4 | 3 / 0 | |
| 0.12.3 | 3 / 0 | |
| 0.12.2 | 3 / 0 | |
| 0.12.1 | 3 / 0 | |
| 0.12.0 | 3 / 0 | |
| 0.11.4 | 3 / 0 | |
| 0.11.3 | 3 / 0 | |
| 0.11.2 | 3 / 0 | |
| 0.11.1 | 3 / 0 | |
| 0.11.0 | 3 / 0 | |
| 0.10.7 | 3 / 0 | |
| 0.10.6 | 3 / 0 | |
| 0.10.5 | 3 / 0 | |
| 0.10.4 | 3 / 0 | |
| 0.10.3 | 3 / 0 | |
| 0.10.2 | 3 / 0 | |
| 0.10.1 | 3 / 0 | |
| 0.8.9 | 3 / 0 | |
| 0.8.8 | 3 / 0 | |
| 0.8.7 | 3 / 0 | |
| 0.8.6 | 3 / 0 | |
| 0.8.5 | 3 / 0 | |
| 0.8.4 | 3 / 0 | |
| 0.8.3 | 3 / 0 | |
| 0.8.2 | 3 / 0 | |
| 0.8.1 | 3 / 0 | |
| 0.8.0 | 3 / 0 | |
| 0.7.5 | 3 / 0 | |
| 0.7.4 | 3 / 0 | |
| 0.7.3 | 3 / 0 | |
| 0.7.2 | 3 / 0 | |
| 0.7.1 | 3 / 0 | |
| 0.7.0 | 3 / 0 | |
| 0.0.8 | 50 / 0 | |
| 0.0.7 | 47 / 0 |
v0.901.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.901.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.901.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.900.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.900.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.900.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.900.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.900.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.900.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.900.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.900.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.803.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.802.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.802.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.802.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.801.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.801.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.801.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.801.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.800.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.800.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.800.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.800.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.800.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.800.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.800.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.12.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.12.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.12.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.12.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.10.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.10.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.10.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.10.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.10.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.10.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.10.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.