@flarehr/apollo-benefits-onboarding
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Config-referenced dep in Vite/Preact bundle; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Core framework dep referenced in build config; expected for this package. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:react-svg | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:jwt-decode | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@microsoft/clarity | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Private org package; no public metadata is expected for internal packages. | ai |
Versions (showing 100 of 669)
| Version | Deps | Published |
|---|---|---|
| 0.1.3613 | 9 / 18 | |
| 0.1.3612 | 9 / 18 | |
| 0.1.3611 | 9 / 18 | |
| 0.1.3610 | 9 / 18 | |
| 0.1.3609 | 9 / 18 | |
| 0.1.3608 | 9 / 18 | |
| 0.1.3607 | 9 / 18 | |
| 0.1.3606 | 9 / 18 | |
| 0.1.3605 | 9 / 18 | |
| 0.1.3604 | 9 / 18 | |
| 0.1.3603 | 9 / 18 | |
| 0.1.3602 | 9 / 18 | |
| 0.1.3601 | 9 / 18 | |
| 0.1.3600 | 9 / 18 | |
| 0.1.3599 | 9 / 18 | |
| 0.1.3598 | 9 / 18 | |
| 0.1.3597 | 9 / 18 | |
| 0.1.3596 | 9 / 18 | |
| 0.1.3595 | 9 / 18 | |
| 0.1.3594 | 9 / 18 | |
| 0.1.3593 | 9 / 18 | |
| 0.1.3592 | 9 / 18 | |
| 0.1.3591 | 9 / 18 | |
| 0.1.3590 | 9 / 18 | |
| 0.1.3589 | 9 / 18 | |
| 0.1.3588 | 9 / 18 | |
| 0.1.3587 | 9 / 18 | |
| 0.1.3586 | 9 / 18 | |
| 0.1.3584 | 9 / 18 | |
| 0.1.3579 | 9 / 18 | |
| 0.1.3578 | 9 / 18 | |
| 0.1.3577 | 9 / 18 | |
| 0.1.3576 | 9 / 18 | |
| 0.1.3575 | 9 / 18 | |
| 0.1.3574 | 9 / 18 | |
| 0.1.3573 | 9 / 18 | |
| 0.1.3572 | 9 / 18 | |
| 0.1.3571 | 9 / 18 | |
| 0.1.3570 | 9 / 18 | |
| 0.1.3569 | 9 / 18 | |
| 0.1.3568 | 9 / 18 | |
| 0.1.3567 | 9 / 18 | |
| 0.1.3566 | 9 / 18 | |
| 0.1.3565 | 9 / 18 | |
| 0.1.3564 | 9 / 18 | |
| 0.1.3563 | 9 / 18 | |
| 0.1.3561 | 9 / 18 | |
| 0.1.3560 | 9 / 18 | |
| 0.1.3559 | 9 / 18 | |
| 0.1.3558 | 9 / 18 | |
| 0.1.3557 | 9 / 18 | |
| 0.1.3556 | 9 / 18 | |
| 0.1.3555 | 9 / 18 | |
| 0.1.3554 | 9 / 18 | |
| 0.1.3553 | 9 / 18 | |
| 0.1.3552 | 9 / 18 | |
| 0.1.3551 | 9 / 18 | |
| 0.1.3550 | 9 / 18 | |
| 0.1.3549 | 9 / 18 | |
| 0.1.3548 | 9 / 18 | |
| 0.1.3547 | 9 / 18 | |
| 0.1.3546 | 9 / 18 | |
| 0.1.3545 | 9 / 18 | |
| 0.1.3544 | 9 / 18 | |
| 0.1.3543 | 9 / 18 | |
| 0.1.3542 | 9 / 18 | |
| 0.1.3541 | 9 / 18 | |
| 0.1.3539 | 9 / 18 | |
| 0.1.3538 | 9 / 18 | |
| 0.1.3537 | 9 / 18 | |
| 0.1.3536 | 9 / 18 | |
| 0.1.3535 | 9 / 18 | |
| 0.1.3534 | 9 / 18 | |
| 0.1.3533 | 9 / 18 | |
| 0.1.3532 | 9 / 18 | |
| 0.1.3531 | 9 / 18 | |
| 0.1.3530 | 9 / 18 | |
| 0.1.3529 | 9 / 18 | |
| 0.1.3528 | 9 / 18 | |
| 0.1.3527 | 9 / 18 | |
| 0.1.3526 | 9 / 18 | |
| 0.1.3525 | 9 / 18 | |
| 0.1.3524 | 9 / 18 | |
| 0.1.3523 | 9 / 18 | |
| 0.1.3522 | 9 / 18 | |
| 0.1.3521 | 9 / 18 | |
| 0.1.3520 | 9 / 18 | |
| 0.1.3519 | 9 / 18 | |
| 0.1.3518 | 9 / 18 | |
| 0.1.3517 | 9 / 18 | |
| 0.1.3516 | 9 / 18 | |
| 0.1.3515 | 9 / 18 | |
| 0.1.3514 | 9 / 18 | |
| 0.1.3513 | 9 / 18 | |
| 0.1.3512 | 9 / 18 | |
| 0.1.3511 | 9 / 18 | |
| 0.1.3510 | 9 / 18 | |
| 0.1.3509 | 9 / 18 | |
| 0.1.3508 | 9 / 18 | |
| 0.1.3507 | 9 / 18 |
v0.1.3613
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3612
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3611
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3610
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3609
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3608
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3607
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3606
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3605
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3604
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3603
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3602
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3601
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3600
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3599
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3598
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3597
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3596
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3595
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3594
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3593
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3592
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3591
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3590
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3589
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3588
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3587
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3586
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3584
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3579
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3578
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3577
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3576
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3575
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3574
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3573
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3572
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3571
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3570
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3569
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3568
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3567
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3566
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3565
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3564
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3563
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3561
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3560
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3559
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3558
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3557
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3556
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3555
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3554
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3553
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3552
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3551
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3550
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3549
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3548
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3547
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3546
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3545
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3544
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3543
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3542
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3541
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3539
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3538
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3537
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3536
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3535
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3534
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3533
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3532
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3531
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3530
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3529
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3528
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3527
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3526
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3525
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3524
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3523
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3522
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3521
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3520
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3519
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3518
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3517
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3516
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3515
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3514
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3513
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3512
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3511
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3510
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3509
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3508
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3507
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.