contentful-management
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:postinstall | AI (install-scripts): postinstall runs patch-package, a standard dev tool for patching dependencies. This is a legitimate, well-known pattern used by the official Contentful SDK and poses no security risk. | ai | |
| phantom-deps | phantom-dep:@types/json-patch | AI (phantom-deps): @types/json-patch is a TypeScript type declaration package; it's normal to declare it as a dependency without direct imports since types are consumed at compile time. | ai | |
| phantom-deps | phantom-dep:lodash.isplainobject | AI (phantom-deps): lodash.isplainobject is a well-known utility bundled via webpack; phantom-dep finding is a stable false positive for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Package migrated to GitHub Actions CI/CD publishing with SLSA provenance attestation; publisher change from contentful-ecosystem to GitHub Actions is the expected outcome of this legitimate automation migration. | ai | |
| provenance | no-provenance | AI (provenance): Established Contentful SDK package with 732 versions; lack of Sigstore provenance is common and not a risk signal for this well-known publisher. | ai | |
| dependencies | unvetted-dep:contentful-sdk-core | AI (dependencies): contentful-sdk-core is a first-party Contentful package; expected dependency for this SDK across all versions. | ai | |
| dependencies | unvetted-dep:@contentful/rich-text-types | AI (dependencies): @contentful/rich-text-types is a first-party Contentful package; expected dependency for this SDK across all versions. | ai | |
| phantom-deps | phantom-dep:process | AI (phantom-deps): process is a Node.js polyfill for browser bundle compatibility via rollup-plugin-polyfill-node; standard pattern for isomorphic SDKs. | ai | |
| phantom-deps | phantom-dep:globals | AI (phantom-deps): globals is used as a browser polyfill in the rollup bundle for this isomorphic SDK; not directly imported in source but legitimately declared as a runtime dep. | ai |
Versions (showing 51 of 192)
| Version | Deps | Published |
|---|---|---|
| 12.5.0 | 6 / 38 | |
| 12.4.0 | 6 / 38 | |
| 12.3.3 | 6 / 38 | |
| 12.3.2 | 6 / 38 | |
| 12.3.1 | 6 / 38 | |
| 12.3.0 | 6 / 38 | |
| 12.2.0 | 6 / 38 | |
| 12.1.0 | 6 / 38 | |
| 12.0.0 | 6 / 38 | |
| 11.76.0 | 5 / 47 | |
| 11.75.0 | 5 / 47 | |
| 11.74.0 | 5 / 47 | |
| 11.73.1 | 5 / 47 | |
| 11.73.0 | 5 / 47 | |
| 11.72.2 | 5 / 47 | |
| 11.72.1 | 5 / 47 | |
| 11.72.0 | 5 / 47 | |
| 11.71.0 | 5 / 47 | |
| 11.70.0 | 5 / 47 | |
| 11.69.3 | 5 / 47 | |
| 11.69.2 | 5 / 47 | |
| 11.69.1 | 5 / 47 | |
| 11.69.0 | 5 / 47 | |
| 11.68.1 | 5 / 47 | |
| 11.68.0 | 5 / 47 | |
| 11.67.2 | 5 / 47 | |
| 11.67.1 | 5 / 47 | |
| 11.67.0 | 5 / 47 | |
| 11.66.0 | 5 / 47 | |
| 11.65.0 | 5 / 47 | |
| 11.64.0 | 5 / 47 | |
| 11.63.1 | 5 / 47 | |
| 11.63.0 | 5 / 47 | |
| 11.62.1 | 5 / 47 | |
| 11.62.0 | 5 / 47 | |
| 11.61.1 | 5 / 47 | |
| 11.61.0 | 5 / 47 | |
| 11.60.4 | 5 / 47 | |
| 11.60.3 | 5 / 47 | |
| 11.60.2 | 5 / 47 | |
| 11.60.1 | 5 / 47 | |
| 11.60.0 | 5 / 47 | |
| 11.59.0 | 5 / 47 | |
| 11.58.1 | 5 / 47 | |
| 11.58.0 | 5 / 47 | |
| 11.57.4 | 5 / 47 | |
| 11.57.3 | 5 / 47 | |
| 11.57.2 | 5 / 47 | |
| 11.57.1 | 5 / 47 | |
| 11.57.0 | 5 / 47 | |
| 11.56.0 | 5 / 47 |
v12.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.3.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.76.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.75.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.74.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.73.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.73.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.72.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.72.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.72.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.71.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.70.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.69.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.69.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.69.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.69.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.68.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.68.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.67.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.67.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.67.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.66.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.65.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.64.0
2 findingsThis version was published by a different npm account than previous versions on 2025-12-09. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.63.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.63.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.62.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.62.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.61.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.61.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.60.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.60.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.60.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.60.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.60.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.59.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.58.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.58.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.57.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.57.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.57.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.57.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.57.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.56.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.