← Home

@defra-fish/gafl-webapp-service

The websales frontend for the GAFL service

28
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

npm-envagedefradigitaladmindefradigitalcijaucourtifarawaydefra

Keywords

rodlicensingfrontendwebapp

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@hapi/catbox-redis AI (dependencies): Official @hapi Redis cache adapter; stable dependency for this package. ai
dependencies unvetted-dep:hapi-i18n AI (dependencies): Known hapi i18n plugin; stable dependency for this package. ai
dependencies unvetted-dep:@hapi/crumb AI (dependencies): Official @hapi CSRF plugin; stable dependency for this package. ai
dependencies unvetted-dep:@hapi/inert AI (dependencies): Official @hapi static file plugin; stable dependency for this package. ai
dependencies unvetted-dep:@hapi/cookie AI (dependencies): Official @hapi cookie auth plugin; stable dependency for this package. ai
dependencies unvetted-dep:@hapi/scooter AI (dependencies): Official @hapi user-agent plugin; stable dependency for this package. ai
dependencies unvetted-dep:@hapi/joi-date AI (dependencies): Official @hapi joi date extension; stable dependency for this package. ai
dependencies unvetted-dep:@defra/hapi-gapi AI (dependencies): DEFRA's own Google Analytics plugin; consistent with package provenance. ai
dependencies unvetted-dep:blankie AI (dependencies): Known hapi CSP plugin; stable dependency for this package. ai
dependencies unvetted-dep:disinfect AI (dependencies): Known hapi sanitization plugin; stable dependency for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with migration to automated CI publishing; not indicative of a takeover given SLSA provenance and unchanged package content. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; legitimate pipeline change for this DEFRA org package. ai
phantom-deps phantom-dep:@hapi/joi-date AI (phantom-deps): Registered as Joi extension at runtime, not directly imported; stable false positive. ai
phantom-deps phantom-dep:semver AI (phantom-deps): semver is a declared dep used in config/build tooling; stable false positive for this package. ai
phantom-deps phantom-dep:@defra/hapi-gapi AI (phantom-deps): Hapi plugin registered dynamically; not directly imported but legitimately used. ai
phantom-deps phantom-dep:govuk-frontend AI (phantom-deps): govuk-frontend is a static asset dep referenced via gulp build pipeline, not direct JS import. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Raw IP (0.0.0.0) appears only in test mock return values, not production network calls. ai

Versions (showing 28 of 28)

Version Deps Published
1.72.0 26 / 9
1.71.0 26 / 9
1.70.1 26 / 9
1.70.0 26 / 9
1.69.0 26 / 9
1.67.0 26 / 9
1.66.0 26 / 9
1.65.0 26 / 9
1.64.0 26 / 9
1.63.0 26 / 9
1.62.0 26 / 9
1.61.0 26 / 9
1.60.0 27 / 9
1.59.0 27 / 9
1.58.0 27 / 9
1.57.0 27 / 9
1.56.0 27 / 9
1.55.0 27 / 9
1.54.0 27 / 9
1.53.0 27 / 9
1.52.0 27 / 9
1.51.0 27 / 9
1.50.0 27 / 9
1.49.0 28 / 9
1.48.0 28 / 9
1.47.0 28 / 9
1.46.0 28 / 9
1.45.0 28 / 9

v1.60.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.59.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.58.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.57.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.56.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.55.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.54.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.53.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.52.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.51.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.50.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.49.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.48.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.47.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.46.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.45.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.