← Home

@defra-fish/gafl-webapp-service

The websales frontend for the GAFL service

11
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

npm-envagedefradigitaladmindefradigitalcijaucourtifarawaydefra

Keywords

rodlicensingfrontendwebapp

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@hapi/catbox-redis AI (dependencies): Official @hapi Redis cache adapter; stable dependency for this package. ai
dependencies unvetted-dep:hapi-i18n AI (dependencies): Known hapi i18n plugin; stable dependency for this package. ai
dependencies unvetted-dep:@hapi/crumb AI (dependencies): Official @hapi CSRF plugin; stable dependency for this package. ai
dependencies unvetted-dep:@hapi/inert AI (dependencies): Official @hapi static file plugin; stable dependency for this package. ai
dependencies unvetted-dep:@hapi/cookie AI (dependencies): Official @hapi cookie auth plugin; stable dependency for this package. ai
dependencies unvetted-dep:@hapi/scooter AI (dependencies): Official @hapi user-agent plugin; stable dependency for this package. ai
dependencies unvetted-dep:@hapi/joi-date AI (dependencies): Official @hapi joi date extension; stable dependency for this package. ai
dependencies unvetted-dep:@defra/hapi-gapi AI (dependencies): DEFRA's own Google Analytics plugin; consistent with package provenance. ai
dependencies unvetted-dep:blankie AI (dependencies): Known hapi CSP plugin; stable dependency for this package. ai
dependencies unvetted-dep:disinfect AI (dependencies): Known hapi sanitization plugin; stable dependency for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with migration to automated CI publishing; not indicative of a takeover given SLSA provenance and unchanged package content. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; legitimate pipeline change for this DEFRA org package. ai
phantom-deps phantom-dep:@hapi/joi-date AI (phantom-deps): Registered as Joi extension at runtime, not directly imported; stable false positive. ai
phantom-deps phantom-dep:semver AI (phantom-deps): semver is a declared dep used in config/build tooling; stable false positive for this package. ai
phantom-deps phantom-dep:@defra/hapi-gapi AI (phantom-deps): Hapi plugin registered dynamically; not directly imported but legitimately used. ai
phantom-deps phantom-dep:govuk-frontend AI (phantom-deps): govuk-frontend is a static asset dep referenced via gulp build pipeline, not direct JS import. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Raw IP (0.0.0.0) appears only in test mock return values, not production network calls. ai

Versions (showing 11 of 11)

Version Deps Published
1.71.0 26 / 9
1.70.1 26 / 9
1.70.0 26 / 9
1.69.0 26 / 9
1.67.0 26 / 9
1.66.0 26 / 9
1.65.0 26 / 9
1.64.0 26 / 9
1.63.0 26 / 9
1.62.0 26 / 9
1.61.0 26 / 9

v1.71.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.70.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.70.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.67.0

2 findings
HIGH Publisher changed: ifarawaydefra → GitHub Actions (on 2026-02-20) provenance

This version was published by a different npm account than previous versions on 2026-02-20. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.66.0

2 findings
HIGH Publisher changed: ifarawaydefra → GitHub Actions (on 2026-01-26) provenance

This version was published by a different npm account than previous versions on 2026-01-26. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.65.0

2 findings
HIGH Publisher changed: ifarawaydefra → GitHub Actions (on 2026-01-22) provenance

This version was published by a different npm account than previous versions on 2026-01-22. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.64.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.63.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.62.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.61.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.