@evergis/react
В данном репозитории находятся специфичные (в отличии от `@evergis/uilib-gl`) для `Evergis Online`, но в целом переиспользуемые на других проектах, построенных на Evergis API, React-компоненты.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Long-established scoped org package; sparse metadata is a stable characteristic, not a spam indicator. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Same pattern — declared dep used transitively or in config, not a security concern. | ai | |
| phantom-deps | phantom-dep:punycode | AI (phantom-deps): Stable false positive for this package's dependency structure. | ai | |
| phantom-deps | phantom-dep:react-is | AI (phantom-deps): Stable false positive for this package's dependency structure. | ai | |
| phantom-deps | phantom-dep:wkt | AI (phantom-deps): Large UI library; deps referenced in config/type files but not directly imported is expected pattern. | ai | |
| phantom-deps | phantom-dep:mapbox-gl-draw | AI (phantom-deps): Stable false positive for this package's dependency structure. | ai | |
| phantom-deps | phantom-dep:@svgdotjs/svg.js | AI (phantom-deps): Stable false positive for this package's dependency structure. | ai | |
| phantom-deps | phantom-dep:styled-system | AI (phantom-deps): Stable false positive for this package's dependency structure. | ai |
Versions (showing 51 of 175)
| Version | Deps | Published |
|---|---|---|
| 4.0.105 | 31 / 29 | |
| 4.0.104 | 31 / 29 | |
| 4.0.103 | 31 / 29 | |
| 4.0.102 | 31 / 29 | |
| 4.0.101 | 31 / 29 | |
| 4.0.100 | 31 / 29 | |
| 4.0.99 | 31 / 29 | |
| 4.0.98 | 31 / 29 | |
| 4.0.97 | 31 / 29 | |
| 4.0.96 | 31 / 29 | |
| 4.0.95 | 31 / 26 | |
| 4.0.94 | 31 / 26 | |
| 4.0.93 | 32 / 27 | |
| 4.0.92 | 32 / 27 | |
| 4.0.91 | 32 / 27 | |
| 4.0.90 | 32 / 27 | |
| 4.0.89 | 32 / 27 | |
| 4.0.88 | 32 / 27 | |
| 4.0.87 | 32 / 27 | |
| 4.0.86 | 32 / 27 | |
| 4.0.80 | 32 / 27 | |
| 4.0.79 | 32 / 27 | |
| 4.0.78 | 32 / 27 | |
| 4.0.76 | 32 / 27 | |
| 4.0.74 | 32 / 27 | |
| 4.0.73 | 32 / 27 | |
| 4.0.72 | 32 / 27 | |
| 4.0.69 | 32 / 27 | |
| 4.0.68 | 32 / 27 | |
| 4.0.67 | 32 / 27 | |
| 4.0.66 | 32 / 27 | |
| 4.0.65 | 32 / 27 | |
| 4.0.64 | 32 / 27 | |
| 4.0.63 | 32 / 27 | |
| 4.0.62 | 32 / 27 | |
| 4.0.61 | 32 / 27 | |
| 4.0.59 | 32 / 27 | |
| 4.0.58 | 32 / 27 | |
| 4.0.57 | 32 / 27 | |
| 4.0.56 | 32 / 27 | |
| 4.0.55 | 32 / 27 | |
| 4.0.54 | 32 / 27 | |
| 4.0.53 | 32 / 27 | |
| 4.0.52 | 32 / 27 | |
| 4.0.51 | 32 / 27 | |
| 4.0.50 | 32 / 27 | |
| 4.0.49 | 32 / 27 | |
| 4.0.48 | 32 / 27 | |
| 4.0.47 | 32 / 27 | |
| 4.0.46 | 32 / 27 | |
| 4.0.45 | 32 / 27 |
v4.0.105
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.104
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (arfeo) than the most recent previously approved version (alexanderbom) on 2026-07-23, but arfeo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.103
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.102
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.101
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexanderbom) than the most recent previously approved version (arfeo) on 2026-07-20, but alexanderbom is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.100
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (arfeo) than the most recent previously approved version (alexanderbom) on 2026-07-16, but arfeo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.99
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.98
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexanderbom) than the most recent previously approved version (arfeo) on 2026-07-16, but alexanderbom is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.97
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (arfeo) than the most recent previously approved version (alexanderbom) on 2026-07-16, but arfeo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.96
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexanderbom) than the most recent previously approved version (arfeo) on 2026-07-15, but alexanderbom is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.95
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (arfeo) than the most recent previously approved version (alexanderbom) on 2026-07-15, but arfeo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.94
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.93
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.92
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.91
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.90
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.89
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.88
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.87
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.86
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alexanderbom) than the most recent previously approved version (arfeo) on 2026-07-01, but alexanderbom is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.