@flarehr/apollo-benefits-onboarding
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Config-referenced dep in Vite/Preact bundle; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Core framework dep referenced in build config; expected for this package. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:react-svg | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:jwt-decode | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@microsoft/clarity | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Private org package; no public metadata is expected for internal packages. | ai |
Versions (showing 65 of 673)
| Version | Deps | Published |
|---|---|---|
| 0.1.3038 | 9 / 18 | |
| 0.1.3037 | 9 / 18 | |
| 0.1.3036 | 9 / 18 | |
| 0.1.3035 | 9 / 18 | |
| 0.1.3034 | 9 / 18 | |
| 0.1.3033 | 9 / 18 | |
| 0.1.3032 | 9 / 18 | |
| 0.1.3031 | 9 / 18 | |
| 0.1.3030 | 9 / 18 | |
| 0.1.3029 | 9 / 18 | |
| 0.1.3028 | 9 / 18 | |
| 0.1.3027 | 9 / 18 | |
| 0.1.3026 | 9 / 18 | |
| 0.1.3024 | 9 / 18 | |
| 0.1.3023 | 9 / 18 | |
| 0.1.3022 | 9 / 18 | |
| 0.1.3021 | 9 / 18 | |
| 0.1.3020 | 9 / 18 | |
| 0.1.3019 | 9 / 18 | |
| 0.1.3018 | 9 / 18 | |
| 0.1.3017 | 9 / 18 | |
| 0.1.3016 | 9 / 18 | |
| 0.1.3015 | 9 / 18 | |
| 0.1.3014 | 9 / 18 | |
| 0.1.3013 | 9 / 18 | |
| 0.1.3012 | 9 / 18 | |
| 0.1.3011 | 9 / 18 | |
| 0.1.3010 | 9 / 18 | |
| 0.1.3009 | 9 / 18 | |
| 0.1.3008 | 9 / 18 | |
| 0.1.3004 | 9 / 18 | |
| 0.1.3003 | 9 / 18 | |
| 0.1.3002 | 9 / 18 | |
| 0.1.3001 | 9 / 18 | |
| 0.1.3000 | 9 / 18 | |
| 0.1.2999 | 9 / 18 | |
| 0.1.2998 | 9 / 18 | |
| 0.1.2997 | 9 / 18 | |
| 0.1.2996 | 9 / 18 | |
| 0.1.2995 | 9 / 18 | |
| 0.1.2994 | 9 / 18 | |
| 0.1.2993 | 9 / 18 | |
| 0.1.2992 | 9 / 18 | |
| 0.1.2991 | 9 / 18 | |
| 0.1.2990 | 9 / 18 | |
| 0.1.2989 | 9 / 18 | |
| 0.1.2988 | 9 / 18 | |
| 0.1.2987 | 9 / 18 | |
| 0.1.2986 | 9 / 18 | |
| 0.1.2985 | 9 / 18 | |
| 0.1.2984 | 9 / 18 | |
| 0.1.2983 | 9 / 18 | |
| 0.1.2982 | 9 / 18 | |
| 0.1.2981 | 9 / 18 | |
| 0.1.2980 | 9 / 18 | |
| 0.1.2979 | 9 / 18 | |
| 0.1.2978 | 9 / 18 | |
| 0.1.2977 | 9 / 18 | |
| 0.1.2976 | 9 / 18 | |
| 0.1.2975 | 9 / 18 | |
| 0.1.2974 | 9 / 18 | |
| 0.1.2973 | 9 / 18 | |
| 0.1.2972 | 9 / 18 | |
| 0.1.2971 | 9 / 18 | |
| 0.1.2970 | 9 / 18 |
v0.1.3038
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3037
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3036
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3035
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3034
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3033
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3032
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3031
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3030
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3029
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3028
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3027
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3026
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3024
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3023
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3022
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3021
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3020
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3019
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3018
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3017
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3016
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3015
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3014
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3013
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3012
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3011
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3010
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3009
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3008
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3004
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3003
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3002
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3001
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3000
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2999
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2998
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2997
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2996
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2995
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2994
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2993
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2992
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2991
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2990
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2989
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2988
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2987
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2986
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2985
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2984
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2983
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2982
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2981
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2980
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2979
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2978
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2977
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2976
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2975
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2974
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2973
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2972
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2971
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2970
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.