@flarehr/apollo-benefits-onboarding
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Config-referenced dep in Vite/Preact bundle; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Core framework dep referenced in build config; expected for this package. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:react-svg | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:jwt-decode | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@microsoft/clarity | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Private org package; no public metadata is expected for internal packages. | ai |
Versions (showing 100 of 673)
| Version | Deps | Published |
|---|---|---|
| 0.1.3276 | 9 / 18 | |
| 0.1.3275 | 9 / 18 | |
| 0.1.3274 | 9 / 18 | |
| 0.1.3273 | 9 / 18 | |
| 0.1.3272 | 9 / 18 | |
| 0.1.3271 | 9 / 18 | |
| 0.1.3270 | 9 / 18 | |
| 0.1.3269 | 9 / 18 | |
| 0.1.3268 | 9 / 18 | |
| 0.1.3266 | 9 / 18 | |
| 0.1.3265 | 9 / 18 | |
| 0.1.3264 | 9 / 18 | |
| 0.1.3263 | 9 / 18 | |
| 0.1.3262 | 9 / 18 | |
| 0.1.3261 | 9 / 18 | |
| 0.1.3260 | 9 / 18 | |
| 0.1.3259 | 9 / 18 | |
| 0.1.3258 | 9 / 18 | |
| 0.1.3257 | 9 / 18 | |
| 0.1.3256 | 9 / 18 | |
| 0.1.3255 | 9 / 18 | |
| 0.1.3254 | 9 / 18 | |
| 0.1.3253 | 9 / 18 | |
| 0.1.3252 | 9 / 18 | |
| 0.1.3251 | 9 / 18 | |
| 0.1.3250 | 9 / 18 | |
| 0.1.3249 | 9 / 18 | |
| 0.1.3248 | 9 / 18 | |
| 0.1.3247 | 9 / 18 | |
| 0.1.3246 | 9 / 18 | |
| 0.1.3245 | 9 / 18 | |
| 0.1.3244 | 9 / 18 | |
| 0.1.3243 | 9 / 18 | |
| 0.1.3242 | 9 / 18 | |
| 0.1.3241 | 9 / 18 | |
| 0.1.3240 | 9 / 18 | |
| 0.1.3239 | 9 / 18 | |
| 0.1.3238 | 9 / 18 | |
| 0.1.3237 | 9 / 18 | |
| 0.1.3236 | 9 / 18 | |
| 0.1.3235 | 9 / 18 | |
| 0.1.3234 | 9 / 18 | |
| 0.1.3233 | 9 / 18 | |
| 0.1.3232 | 9 / 18 | |
| 0.1.3231 | 9 / 18 | |
| 0.1.3230 | 9 / 18 | |
| 0.1.3229 | 9 / 18 | |
| 0.1.3228 | 9 / 18 | |
| 0.1.3227 | 9 / 18 | |
| 0.1.3226 | 9 / 18 | |
| 0.1.3225 | 9 / 18 | |
| 0.1.3224 | 9 / 18 | |
| 0.1.3222 | 9 / 18 | |
| 0.1.3221 | 9 / 18 | |
| 0.1.3220 | 9 / 18 | |
| 0.1.3219 | 9 / 18 | |
| 0.1.3218 | 9 / 18 | |
| 0.1.3217 | 9 / 18 | |
| 0.1.3216 | 9 / 18 | |
| 0.1.3215 | 9 / 18 | |
| 0.1.3214 | 9 / 18 | |
| 0.1.3213 | 9 / 18 | |
| 0.1.3212 | 9 / 18 | |
| 0.1.3211 | 9 / 18 | |
| 0.1.3210 | 9 / 18 | |
| 0.1.3209 | 9 / 18 | |
| 0.1.3208 | 9 / 18 | |
| 0.1.3207 | 9 / 18 | |
| 0.1.3206 | 9 / 18 | |
| 0.1.3205 | 9 / 18 | |
| 0.1.3204 | 9 / 18 | |
| 0.1.3203 | 9 / 18 | |
| 0.1.3202 | 9 / 18 | |
| 0.1.3200 | 9 / 18 | |
| 0.1.3198 | 9 / 18 | |
| 0.1.3197 | 9 / 18 | |
| 0.1.3193 | 9 / 18 | |
| 0.1.3192 | 9 / 18 | |
| 0.1.3191 | 9 / 18 | |
| 0.1.3190 | 9 / 18 | |
| 0.1.3189 | 9 / 18 | |
| 0.1.3188 | 9 / 18 | |
| 0.1.3187 | 9 / 18 | |
| 0.1.3186 | 9 / 18 | |
| 0.1.3185 | 9 / 18 | |
| 0.1.3184 | 9 / 18 | |
| 0.1.3183 | 9 / 18 | |
| 0.1.3182 | 9 / 18 | |
| 0.1.3181 | 9 / 18 | |
| 0.1.3180 | 9 / 18 | |
| 0.1.3179 | 9 / 18 | |
| 0.1.3178 | 9 / 18 | |
| 0.1.3177 | 9 / 18 | |
| 0.1.3176 | 9 / 18 | |
| 0.1.3175 | 9 / 18 | |
| 0.1.3174 | 9 / 18 | |
| 0.1.3173 | 9 / 18 | |
| 0.1.3171 | 9 / 18 | |
| 0.1.3169 | 9 / 18 | |
| 0.1.3168 | 9 / 18 |
v0.1.3276
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3275
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3274
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3273
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3272
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3271
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3270
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3269
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3268
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3266
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3265
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3264
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3263
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3262
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3261
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3260
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3259
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3258
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3257
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3256
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3255
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3254
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3253
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3252
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3251
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3250
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3249
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3248
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3247
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3246
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3245
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3244
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3243
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3242
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3241
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3240
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3239
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3238
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3237
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3236
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3235
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3234
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3233
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3232
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3231
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3230
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3229
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3228
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3227
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3226
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3225
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3224
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3222
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3221
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3220
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3219
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3218
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3217
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3216
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3215
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3214
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3213
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3212
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3211
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3210
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3209
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3208
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3207
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3206
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3205
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3204
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3203
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3202
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3200
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3198
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3197
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3193
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3192
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3191
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3190
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3189
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3188
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3187
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3186
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3185
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3184
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3183
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3182
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3181
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3180
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3179
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3178
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3177
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3176
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3175
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3174
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3173
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3171
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3169
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3168
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.