@adobe/data
Adobe data oriented programming library
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-removed | AI (maintainer-change): Paired with new maintainer add, consistent with normal team handoff. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Adobe org publisher with strong track record; likely internal team rotation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Diff vs prior approved shows no material dep/script changes; likely docs/build artifacts. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Binary is a WASM/native artifact from the documented AssemblyScript build pipeline; stable for this package. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Used to generate typed-buffer struct readers from layout metadata; controlled input, not user-supplied arbitrary code. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get used in a Proxy get trap for transparent property forwarding — idiomatic JS, not obfuscation. | ai | |
| dependencies | unvetted-dep:@spectrum-web-components/action-group | AI (dependencies): Adobe's official Spectrum Web Components library; expected dep for this Adobe package. | ai | |
| dependencies | unvetted-dep:@spectrum-web-components/card | AI (dependencies): Adobe's official Spectrum Web Components library; expected dep for this Adobe package. | ai | |
| phantom-deps | phantom-dep:@lit/context | AI (phantom-deps): Lit context referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@spectrum-web-components/card | AI (phantom-deps): SWC components loaded via side-effect/HTML; not directly imported in JS but legitimately used. | ai | |
| phantom-deps | phantom-dep:@spectrum-web-components/styles | AI (phantom-deps): SWC components loaded via side-effect/HTML; not directly imported in JS but legitimately used. | ai | |
| phantom-deps | phantom-dep:@spectrum-web-components/button | AI (phantom-deps): SWC components loaded via side-effect/HTML; not directly imported in JS but legitimately used. | ai | |
| phantom-deps | phantom-dep:@spectrum-web-components/theme | AI (phantom-deps): SWC components loaded via side-effect/HTML; not directly imported in JS but legitimately used. | ai |
Versions (showing 51 of 142)
| Version | Deps | Published |
|---|---|---|
| 0.9.83 | 3 / 35 | |
| 0.9.82 | 3 / 35 | |
| 0.9.81 | 3 / 35 | |
| 0.9.80 | 3 / 35 | |
| 0.9.79 | 3 / 35 | |
| 0.9.78 | 3 / 35 | |
| 0.9.77 | 3 / 35 | |
| 0.9.76 | 3 / 35 | |
| 0.9.75 | 3 / 35 | |
| 0.9.74 | 3 / 35 | |
| 0.9.73 | 3 / 35 | |
| 0.9.72 | 3 / 35 | |
| 0.9.70 | 3 / 35 | |
| 0.9.69 | 3 / 35 | |
| 0.9.68 | 3 / 35 | |
| 0.9.67 | 3 / 35 | |
| 0.9.66 | 3 / 35 | |
| 0.9.65 | 3 / 35 | |
| 0.9.64 | 3 / 35 | |
| 0.9.63 | 3 / 35 | |
| 0.9.62 | 3 / 35 | |
| 0.9.61 | 3 / 35 | |
| 0.9.60 | 3 / 35 | |
| 0.9.59 | 3 / 35 | |
| 0.9.58 | 3 / 35 | |
| 0.9.57 | 3 / 35 | |
| 0.9.56 | 3 / 35 | |
| 0.9.55 | 3 / 35 | |
| 0.9.54 | 3 / 35 | |
| 0.9.53 | 3 / 35 | |
| 0.9.52 | 3 / 35 | |
| 0.9.51 | 3 / 35 | |
| 0.9.50 | 3 / 35 | |
| 0.9.48 | 3 / 35 | |
| 0.9.47 | 3 / 35 | |
| 0.9.46 | 3 / 35 | |
| 0.9.45 | 3 / 35 | |
| 0.9.44 | 3 / 35 | |
| 0.9.43 | 3 / 35 | |
| 0.9.42 | 3 / 35 | |
| 0.9.41 | 3 / 35 | |
| 0.9.40 | 3 / 35 | |
| 0.9.39 | 3 / 35 | |
| 0.9.37 | 3 / 35 | |
| 0.9.36 | 3 / 35 | |
| 0.9.35 | 3 / 35 | |
| 0.9.34 | 3 / 35 | |
| 0.9.33 | 2 / 35 | |
| 0.9.32 | 2 / 35 | |
| 0.9.31 | 2 / 35 | |
| 0.9.30 | 2 / 35 |
v0.9.83
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.82
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.81
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.80
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.79
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.78
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.77
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.76
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.75
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.74
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.