@firestone-hs/simulate-bgs-battle
``` npm install npm run test-board ```
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@firestone-hs/hs-replay-xml-parser | AI (phantom-deps): Same org scope; dependency is declared and likely bundled into dist rather than directly imported in source. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 700+ versions; no provenance is consistent across all prior releases. | ai |
Versions (showing 19 of 419)
| Version | Deps | Published |
|---|---|---|
| 1.1.283 | 2 / 19 | |
| 1.1.282 | 2 / 19 | |
| 1.1.281 | 2 / 19 | |
| 1.1.280 | 2 / 19 | |
| 1.1.279 | 2 / 19 | |
| 1.1.278 | 2 / 19 | |
| 1.1.277 | 2 / 19 | |
| 1.1.276 | 2 / 19 | |
| 1.1.275 | 2 / 19 | |
| 1.1.274 | 2 / 19 | |
| 1.1.273 | 2 / 19 | |
| 1.1.272 | 2 / 19 | |
| 1.1.271 | 2 / 19 | |
| 1.1.270 | 2 / 19 | |
| 1.1.268 | 2 / 19 | |
| 1.1.267 | 2 / 19 | |
| 1.1.266 | 2 / 19 | |
| 1.1.265 | 2 / 19 | |
| 1.1.264 | 2 / 19 |
v1.1.283
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.282
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.281
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.280
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.279
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.278
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.277
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.276
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.275
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.274
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.273
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.272
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.271
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.270
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.268
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.267
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.266
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.265
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.264
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.