@apollosproject/canvas-embeds
Apollos React embed widgets
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@apollosproject/donation-embed | AI (phantom-deps): Same-org workspace dependency. | ai | |
| phantom-deps | phantom-dep:camelcase | AI (phantom-deps): Monorepo config reference, not runtime import. | ai | |
| phantom-deps | phantom-dep:react-instantsearch-hooks-web | AI (phantom-deps): Monorepo config reference, not runtime import. | ai | |
| phantom-deps | phantom-dep:@algolia/autocomplete-js | AI (phantom-deps): Monorepo config reference, not runtime import. | ai | |
| phantom-deps | phantom-dep:react-instantsearch-dom | AI (phantom-deps): Monorepo config reference, not runtime import. | ai | |
| phantom-deps | phantom-dep:@stripe/react-stripe-js | AI (phantom-deps): Monorepo config reference, not runtime import. | ai | |
| phantom-deps | phantom-dep:resolve | AI (phantom-deps): Monorepo config reference, not runtime import. | ai | |
| phantom-deps | phantom-dep:@segment/analytics-next | AI (phantom-deps): Monorepo config reference, not runtime import. | ai | |
| phantom-deps | phantom-dep:@stripe/stripe-js | AI (phantom-deps): Monorepo config reference, not runtime import. | ai | |
| phantom-deps | phantom-dep:react-player | AI (phantom-deps): Monorepo config reference, not runtime import. | ai | |
| phantom-deps | phantom-dep:amplitude-js | AI (phantom-deps): Monorepo config reference, not runtime import. | ai | |
| phantom-deps | phantom-dep:@algolia/autocomplete-core | AI (phantom-deps): Config-referenced Algolia deps; stable pattern in this monorepo package. | ai | |
| phantom-deps | phantom-dep:@algolia/autocomplete-plugin-query-suggestions | AI (phantom-deps): Config-referenced Algolia deps; stable pattern in this monorepo package. | ai | |
| phantom-deps | phantom-dep:@algolia/autocomplete-plugin-recent-searches | AI (phantom-deps): Config-referenced Algolia deps; stable pattern in this monorepo package. | ai | |
| phantom-deps | phantom-dep:@algolia/autocomplete-preset-algolia | AI (phantom-deps): Config-referenced Algolia deps; stable pattern in this monorepo package. | ai | |
| phantom-deps | phantom-dep:@algolia/autocomplete-theme-classic | AI (phantom-deps): Config-referenced Algolia deps; stable pattern in this monorepo package. | ai | |
| phantom-deps | phantom-dep:@apollosproject/cluster-client | AI (phantom-deps): Same-org workspace dependency; expected in monorepo structure. | ai | |
| phantom-deps | phantom-dep:react-transition-group | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@styled-system/theme-get | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@apollosproject/analytics | AI (phantom-deps): Workspace dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:apollo3-cache-persist | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:base-64 | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:web-vitals | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@sentry/react | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:algoliasearch | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:styled-system | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:react-image-crop | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:react-router-dom | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:styled-components | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:apollo-upload-client | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:react-multi-carousel | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@phosphor-icons/react | AI (phantom-deps): Config-referenced dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:color | AI (phantom-deps): Monorepo/build-config dep, not a security concern. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Monorepo/build-config dep, not a security concern. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): Monorepo/build-config dep, not a security concern. | ai | |
| phantom-deps | phantom-dep:tldts | AI (phantom-deps): Monorepo/build-config dep, not a security concern. | ai | |
| dependencies | unvetted-dep:@apollosproject/analytics | AI (dependencies): Internal workspace sibling package, not external unvetted code. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Monorepo config/build dep pattern, stable false positive. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo-wide automated version bump pattern across 1443 versions. | ai | |
| dependencies | unvetted-dep:@apollosproject/cluster-client | AI (dependencies): Internal workspace sibling package, not external unvetted code. | ai | |
| dependencies | unvetted-dep:@apollosproject/canvas-ui-web | AI (dependencies): Internal workspace sibling package, not external unvetted code. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Monorepo workspace pattern; stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 1251 versions; lack of provenance is common and not a risk signal here. | ai | |
| phantom-deps | phantom-dep:@apollosproject/canvas-ui-web | AI (phantom-deps): Same org scope, workspace dependency; stable false positive. | ai | |
| phantom-deps | phantom-dep:@apollo/client | AI (phantom-deps): Monorepo workspace pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:graphql | AI (phantom-deps): Monorepo workspace pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Monorepo workspace pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Monorepo workspace pattern; deps declared at root, not directly imported in sub-package. | ai |
Versions (showing 37 of 37)
| Version | Deps | Published |
|---|---|---|
| 2.1.1555 | 36 / 45 | |
| 2.1.1553 | 36 / 45 | |
| 2.1.1527 | 36 / 45 | |
| 2.1.1520 | 36 / 45 | |
| 2.1.1512 | 36 / 45 | |
| 2.1.1494 | 36 / 45 | |
| 2.1.1485 | 36 / 45 | |
| 2.1.1484 | 36 / 45 | |
| 2.1.1477 | 36 / 45 | |
| 2.1.1473 | 36 / 45 | |
| 2.1.1472 | 36 / 45 | |
| 2.1.1471 | 36 / 45 | |
| 2.1.1470 | 36 / 45 | |
| 2.1.1469 | 36 / 45 | |
| 2.1.1468 | 36 / 45 | |
| 2.1.1464 | 36 / 45 | |
| 2.1.1463 | 36 / 45 | |
| 2.1.1462 | 36 / 45 | |
| 2.1.1461 | 36 / 45 | |
| 2.1.1453 | 36 / 45 | |
| 2.1.1450 | 36 / 45 | |
| 2.1.1443 | 36 / 45 | |
| 2.1.1435 | 36 / 45 | |
| 2.1.1415 | 36 / 45 | |
| 2.1.1384 | 36 / 45 | |
| 2.1.1364 | 36 / 45 | |
| 2.1.1362 | 36 / 45 | |
| 2.1.1345 | 36 / 45 | |
| 2.1.1288 | 40 / 45 | |
| 2.1.1259 | 40 / 52 | |
| 2.1.1257 | 40 / 52 | |
| 2.1.1254 | 40 / 52 | |
| 2.1.1251 | 40 / 52 | |
| 2.1.1154 | 40 / 52 | |
| 2.1.970 | 44 / 51 | |
| 2.1.684 | 44 / 50 | |
| 2.1.590 | 44 / 50 |
v2.1.1555
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1553
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1527
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1520
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1512
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1494
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1485
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1484
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1477
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1473
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1472
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1471
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1470
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1469
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1468
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1464
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1463
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1462
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1461
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1453
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1450
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1443
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1435
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1415
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.970
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.684
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.590
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.