← Home

@esfaenza/core

This library was generated with [Angular CLI](https://github.com/angular/angular-cli) version 15.2.0.

21
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

energysoftwarefaenza

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@esfaenza/cytoscape-html-node AI (phantom-deps): Same-org scoped package; stable pattern for this package. ai
phantom-deps phantom-dep:@esfaenza/pace AI (phantom-deps): Same-org scoped package; stable pattern for this package. ai
phantom-deps phantom-dep:@esfaenza/rrule AI (phantom-deps): Same-org scoped package; stable pattern for this package. ai
phantom-deps phantom-dep:@esfaenza/es-pager AI (phantom-deps): Same-org scoped package; stable pattern for this package. ai
phantom-deps phantom-dep:@esfaenza/treecomp AI (phantom-deps): Same-org scoped package; stable pattern for this package. ai
phantom-deps phantom-dep:@esfaenza/es-commands AI (phantom-deps): Same-org scoped package; stable pattern for this package. ai
phantom-deps phantom-dep:@esfaenza/es-diagrams AI (phantom-deps): Same-org scoped package; stable pattern for this package. ai
phantom-deps phantom-dep:dagre AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:cytoscape AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@fullcalendar/core AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@amcharts/amcharts4 AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:ckeditor5 AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:xlsx AI (phantom-deps): Large Angular lib; config-referenced deps are expected false positives. ai
source-diff encoded-string-file:fesm2022/esfaenza-core-services.mjs AI (source-diff): Base64 is an embedded stock avatar PNG data URI, not a payload. ai
publish-pattern new-deps-added AI (publish-pattern): Angular framework deps matching declared peerDependencies, not unvetted third-party additions. ai
dependencies unvetted-dep:xlsx AI (dependencies): Well-known official sheetjs.com CDN distribution, long-standing pattern for this lib. ai
npm-metadata url-dep:xlsx AI (npm-metadata): SheetJS distributes via CDN tarball; this is the documented install method for xlsx post-license change. ai
typosquat typosquat.levenshtein:cors AI (typosquat): Scoped Angular framework package with 539 versions and 963 days history; not a typosquat of cors. ai

Versions (showing 21 of 21)

Version Deps Published
20.3.17 96 / 0
20.3.13 96 / 0
20.3.12 96 / 0
20.3.5 96 / 0
19.2.249 87 / 0
19.2.247 87 / 0
19.2.241 89 / 0
19.2.240 89 / 0
19.2.239 89 / 0
19.2.238 89 / 0
19.2.237 89 / 0
19.2.236 89 / 0
19.2.235 89 / 0
19.2.234 89 / 0
19.2.233 89 / 0
19.2.225 74 / 0
19.2.224 74 / 0
19.2.220 74 / 0
19.2.219 74 / 0
19.2.218 74 / 0
19.2.203 74 / 0

v20.3.17

2 findings
HIGH Long encoded string in modified file: fesm2022/esfaenza-core-services.mjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v19.2.225

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v19.2.224

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.