@compas-oscd/open-scd
A bottom-up substation configuration designer for projects described using SCL `IEC 61850-6` Edition 2 or greater.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@openscd/core | AI (dependencies): Aliased to @compas-oscd/core — same org's internal package, stable pattern for this fork. | ai | |
| dependencies | unvetted-dep:@openscd/xml | AI (dependencies): Aliased to @compas-oscd/xml via npm alias; consistent with this fork's pattern of replacing @openscd/* with @compas-oscd/* equivalents. | ai | |
| phantom-deps | phantom-dep:panzoom | AI (phantom-deps): panzoom referenced in config files; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@material/mwc-fab | AI (phantom-deps): MWC web components loaded via HTML/config, not direct JS import; stable false positive. | ai | |
| phantom-deps | phantom-dep:lit | AI (phantom-deps): lit is a peer/bundled dep in a web-component package; phantom-dep heuristic fires on config references. | ai | |
| phantom-deps | phantom-dep:@material/mwc-textarea | AI (phantom-deps): MWC component loaded via config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@openscd/oscd-api | AI (phantom-deps): API types package referenced in config; phantom-dep false positive for this package. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): marked used via config/bundler, not direct import; stable false positive for this package. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 0.34.51 | 27 / 34 | |
| 0.34.50 | 27 / 34 | |
| 0.34.49 | 27 / 34 | |
| 0.34.48 | 27 / 34 | |
| 0.34.47 | 27 / 34 | |
| 0.34.46 | 27 / 34 | |
| 0.34.45 | 27 / 34 | |
| 0.34.44 | 26 / 34 | |
| 0.34.43 | 26 / 34 | |
| 0.34.42 | 26 / 34 | |
| 0.34.41 | 26 / 34 | |
| 0.34.40 | 26 / 34 | |
| 0.34.39 | 26 / 34 | |
| 0.34.38 | 26 / 34 | |
| 0.34.37 | 26 / 34 | |
| 0.34.36 | 26 / 34 | |
| 0.34.35 | 26 / 34 | |
| 0.34.34 | 26 / 34 | |
| 0.34.33 | 26 / 34 | |
| 0.34.32 | 26 / 34 | |
| 0.34.31 | 26 / 34 | |
| 0.34.27 | 26 / 34 | |
| 0.34.25 | 26 / 34 | |
| 0.34.20 | 26 / 34 | |
| 0.34.18 | 26 / 34 | |
| 0.34.15 | 26 / 34 | |
| 0.34.10 | 26 / 34 | |
| 0.34.8 | 26 / 34 |
v0.34.51
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.50
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.48
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.47
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.46
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.45
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.44
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.34.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.34.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.34.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.