@egovernments/digit-ui-module-core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Both publishers are within the @egovernments org; transition appears legitimate with no code changes. | ai | |
| provenance | no-provenance | AI (provenance): Established eGov package with 421 versions; lack of provenance is consistent across all versions and not a risk indicator here. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom declared as peer/runtime dep in package.json; phantom-dep heuristic fires due to bundler pattern, not a real issue. | ai | |
| phantom-deps | phantom-dep:react-tooltip | AI (phantom-deps): react-tooltip declared as runtime dep; phantom-dep heuristic fires due to bundler pattern, not a real issue. | ai |
Versions (showing 51 of 72)
| Version | Deps | Published |
|---|---|---|
| 1.9.15 | 12 / 0 | |
| 1.9.14 | 12 / 0 | |
| 1.9.12 | 12 / 0 | |
| 1.9.11 | 12 / 0 | |
| 1.9.10 | 12 / 0 | |
| 1.9.9 | 12 / 0 | |
| 1.9.8 | 12 / 0 | |
| 1.9.7 | 12 / 0 | |
| 1.9.6 | 12 / 0 | |
| 1.9.5 | 12 / 0 | |
| 1.9.4 | 12 / 0 | |
| 1.9.3 | 12 / 0 | |
| 1.9.2 | 12 / 0 | |
| 1.9.1 | 12 / 0 | |
| 1.9.0 | 12 / 0 | |
| 1.8.55 | 12 / 0 | |
| 1.8.54 | 12 / 0 | |
| 1.8.53 | 12 / 0 | |
| 1.8.52 | 12 / 0 | |
| 1.8.51 | 12 / 0 | |
| 1.8.50 | 12 / 0 | |
| 1.8.49 | 12 / 0 | |
| 1.8.48 | 12 / 0 | |
| 1.8.47 | 12 / 0 | |
| 1.8.46 | 12 / 0 | |
| 1.8.45 | 12 / 0 | |
| 1.8.44 | 12 / 0 | |
| 1.8.43 | 12 / 0 | |
| 1.8.42 | 12 / 0 | |
| 1.8.41 | 12 / 0 | |
| 1.8.40 | 12 / 0 | |
| 1.8.39 | 12 / 0 | |
| 1.8.38 | 12 / 0 | |
| 1.8.37 | 12 / 0 | |
| 1.8.36 | 12 / 0 | |
| 1.8.35 | 12 / 0 | |
| 1.8.34 | 12 / 0 | |
| 1.8.33 | 12 / 0 | |
| 1.8.32 | 12 / 0 | |
| 1.8.31 | 12 / 0 | |
| 1.8.30 | 12 / 0 | |
| 1.8.29 | 12 / 0 | |
| 1.8.28 | 12 / 0 | |
| 1.8.27 | 12 / 0 | |
| 1.8.26 | 12 / 0 | |
| 1.8.25 | 12 / 0 | |
| 1.8.24 | 12 / 0 | |
| 1.8.23 | 12 / 0 | |
| 1.8.22 | 12 / 0 | |
| 1.8.21 | 12 / 0 | |
| 1.8.20 | 12 / 0 |
v1.8.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.