@arcgis/lumina-compiler
**No Esri Technical Support included.**
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Publisher has strong approval history; likely CI/CD environment change during major version bump, not a supply-chain indicator. | ai | |
| phantom-deps | phantom-dep:mime-types | AI (phantom-deps): mime-types is a declared runtime dep used indirectly; stable false positive for this compiler tooling package. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Chalk is a declared runtime dep used indirectly via config/build tooling; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:js-beautify | AI (phantom-deps): js-beautify is a declared runtime dep used indirectly; stable false positive for this compiler tooling package. | ai | |
| phantom-deps | phantom-dep:sass-embedded | AI (phantom-deps): sass-embedded is a declared runtime dep used indirectly via vite/build pipeline; stable false positive. | ai | |
| phantom-deps | phantom-dep:vitest-fail-on-console | AI (phantom-deps): vitest-fail-on-console is a declared runtime dep used indirectly via vitest config; stable false positive. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @vitest/expect and @vitest/runner are canonical vitest sub-packages matching the declared peer dep; not suspicious. | ai | |
| provenance | publisher-changed | AI (provenance): dan11669 is an established @arcgis org publisher with 20 approved packages; transition appears legitimate. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal @arcgis scoped package; missing repo/keywords/README detail is typical for enterprise-internal packages. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit runtime dependency, commonly used without direct imports. | ai |
Versions (showing 39 of 39)
| Version | Deps | Published |
|---|---|---|
| 5.1.14 | 10 / 0 | |
| 5.1.13 | 10 / 0 | |
| 5.1.12 | 10 / 0 | |
| 5.1.11 | 10 / 0 | |
| 5.1.10 | 10 / 0 | |
| 5.1.9 | 10 / 0 | |
| 5.1.8 | 10 / 0 | |
| 5.1.7 | 10 / 0 | |
| 5.1.6 | 10 / 0 | |
| 5.1.5 | 10 / 0 | |
| 5.1.4 | 10 / 0 | |
| 5.1.3 | 10 / 0 | |
| 5.1.2 | 10 / 0 | |
| 5.1.1 | 10 / 0 | |
| 5.1.0 | 10 / 0 | |
| 5.0.19 | 11 / 0 | |
| 5.0.18 | 11 / 0 | |
| 5.0.17 | 11 / 0 | |
| 5.0.16 | 11 / 0 | |
| 5.0.15 | 11 / 0 | |
| 5.0.14 | 11 / 0 | |
| 5.0.13 | 11 / 0 | |
| 5.0.12 | 11 / 0 | |
| 5.0.11 | 11 / 0 | |
| 5.0.10 | 11 / 0 | |
| 5.0.9 | 11 / 0 | |
| 5.0.8 | 11 / 0 | |
| 5.0.7 | 11 / 0 | |
| 5.0.6 | 11 / 0 | |
| 5.0.5 | 11 / 0 | |
| 5.0.4 | 11 / 0 | |
| 5.0.3 | 11 / 0 | |
| 5.0.2 | 11 / 0 | |
| 5.0.1 | 11 / 0 | |
| 5.0.0 | 11 / 0 | |
| 4.34.9 | 10 / 0 | |
| 4.34.8 | 10 / 0 | |
| 4.34.7 | 10 / 0 | |
| 4.32.16 | 16 / 0 |
v5.1.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.