@eka-care/apollo-assist
A lightweight SDK for integrating medical assistant chatbot functionality into your applications.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): UI utility library; used indirectly in bundled components. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Common utility; likely used indirectly in bundled code. | ai | |
| phantom-deps | phantom-dep:jszip | AI (phantom-deps): Bundled utility; used indirectly in widget code. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Peer dependency for React components; used indirectly. | ai | |
| phantom-deps | phantom-dep:zustand | AI (phantom-deps): State management; used indirectly in bundled components. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Peer dependency; used indirectly in bundled code. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Markdown plugin; used indirectly in bundled components. | ai | |
| phantom-deps | phantom-dep:lucide-react | AI (phantom-deps): Icon library; used indirectly in bundled UI. | ai | |
| phantom-deps | phantom-dep:react-markdown | AI (phantom-deps): Markdown renderer; used indirectly in bundled code. | ai | |
| phantom-deps | phantom-dep:tailwind-merge | AI (phantom-deps): Tailwind utility; used indirectly in bundled components. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-slot | AI (phantom-deps): Radix UI primitive; used indirectly in bundled components. | ai | |
| phantom-deps | phantom-dep:class-variance-authority | AI (phantom-deps): Component styling utility; used indirectly in bundled code. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 0.1.45 | 12 / 14 | |
| 0.1.44 | 12 / 14 | |
| 0.1.43 | 12 / 14 | |
| 0.1.42 | 12 / 14 | |
| 0.1.41 | 12 / 14 | |
| 0.1.40 | 12 / 14 | |
| 0.1.39 | 12 / 14 | |
| 0.1.38 | 12 / 14 | |
| 0.1.37 | 12 / 14 | |
| 0.1.36 | 12 / 14 | |
| 0.1.35 | 12 / 14 | |
| 0.1.34 | 12 / 14 | |
| 0.1.33 | 12 / 14 | |
| 0.1.32 | 12 / 14 | |
| 0.1.30 | 12 / 14 |
v0.1.44
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.