@artel/standard-edition
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@artel/ru-platform-javascript | AI (phantom-deps): Same-org phantom dep, consistent with all other @artel/* phantom deps already accepted. | ai | |
| dependencies | unvetted-dep:@artel/en-user-interface | AI (dependencies): Same-org @artel/* dependency; consistent with this package's role as a bundle of artel components. | ai | |
| dependencies | unvetted-dep:@artel/ru-user-interface | AI (dependencies): Same-org @artel/* dependency; consistent with this package's role as a bundle of artel components. | ai | |
| bogus-package | bogus-package | AI (bogus-package): No-repo/tiny-payload pattern is consistent across all @artel distribution packages; not indicative of spam. | ai | |
| phantom-deps | phantom-dep:@artel/en-user-interface | AI (phantom-deps): Same-org @artel package; consistent phantom-dep pattern for this package. | ai | |
| phantom-deps | phantom-dep:@artel/ru-user-interface | AI (phantom-deps): Same-org @artel package; consistent phantom-dep pattern for this package. | ai | |
| phantom-deps | phantom-dep:@artel/ru-artel-system | AI (phantom-deps): Same-org @artel package; consistent phantom-dep pattern for this package. | ai | |
| phantom-deps | phantom-dep:@artel/en-artel-system | AI (phantom-deps): Same-org @artel package; consistent phantom-dep pattern for this package. | ai | |
| phantom-deps | phantom-dep:@artel/ru-compiler | AI (phantom-deps): Same-org @artel package; phantom-dep pattern is stable across this package's many versions. | ai | |
| phantom-deps | phantom-dep:@artel/ru-verstak | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/en-reactivity | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/ru-reactivity | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/en-platform-javascript | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/en-platform-javascript-intl | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/en-math | AI (phantom-deps): Umbrella package; deps declared for re-export, not direct import. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@artel/ru-platform-javascript-intl | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/ru-platform-javascript-node | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/en-platform-javascript-console | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/artc | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/en-compiler | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/en-platform-javascript-node | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/ru-math | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/en-dialog | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/ru-dialog | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/en-browser | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/en-logging | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/en-verstak | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/ru-browser | AI (phantom-deps): Same umbrella pattern. | ai | |
| phantom-deps | phantom-dep:@artel/ru-logging | AI (phantom-deps): Same umbrella pattern. | ai |
Versions (showing 59 of 59)
v0.9.26044
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.26042
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.26020
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.25192
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.25191
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.