@egovernments/digit-ui-module-core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Both publishers are within the @egovernments org; transition appears legitimate with no code changes. | ai | |
| provenance | no-provenance | AI (provenance): Established eGov package with 421 versions; lack of provenance is consistent across all versions and not a risk indicator here. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom declared as peer/runtime dep in package.json; phantom-dep heuristic fires due to bundler pattern, not a real issue. | ai | |
| phantom-deps | phantom-dep:react-tooltip | AI (phantom-deps): react-tooltip declared as runtime dep; phantom-dep heuristic fires due to bundler pattern, not a real issue. | ai |
Versions (showing 36 of 36)
| Version | Deps | Published |
|---|---|---|
| 1.9.15 | 12 / 0 | |
| 1.9.14 | 12 / 0 | |
| 1.9.12 | 12 / 0 | |
| 1.9.11 | 12 / 0 | |
| 1.9.10 | 12 / 0 | |
| 1.9.9 | 12 / 0 | |
| 1.9.8 | 12 / 0 | |
| 1.9.7 | 12 / 0 | |
| 1.9.6 | 12 / 0 | |
| 1.9.5 | 12 / 0 | |
| 1.9.4 | 12 / 0 | |
| 1.9.3 | 12 / 0 | |
| 1.9.2 | 12 / 0 | |
| 1.9.1 | 12 / 0 | |
| 1.9.0 | 12 / 0 | |
| 1.8.55 | 12 / 0 | |
| 1.8.54 | 12 / 0 | |
| 1.8.53 | 12 / 0 | |
| 1.8.52 | 12 / 0 | |
| 1.8.51 | 12 / 0 | |
| 1.8.50 | 12 / 0 | |
| 1.8.49 | 12 / 0 | |
| 1.8.48 | 12 / 0 | |
| 1.8.47 | 12 / 0 | |
| 1.8.46 | 12 / 0 | |
| 1.8.45 | 12 / 0 | |
| 1.8.44 | 12 / 0 | |
| 1.8.43 | 12 / 0 | |
| 1.8.42 | 12 / 0 | |
| 1.8.41 | 12 / 0 | |
| 1.8.40 | 12 / 0 | |
| 1.8.39 | 12 / 0 | |
| 1.8.38 | 12 / 0 | |
| 1.8.37 | 12 / 0 | |
| 1.8.36 | 12 / 0 | |
| 1.7.40 | 10 / 0 |
v1.9.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.14
2 findingsThis version was published by a different npm account than previous versions on 2026-03-12. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.55
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.54
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.53
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.52
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.51
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.50
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.49
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.48
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.47
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.46
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.45
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.44
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.