@flarehr/benefits-plan-assessment
In index.html update values for `profile-id`, `assessment-id` and `access-token`.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:downshift | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:use-debounce | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:react-router-dom | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:react-transition-group | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:@contentful/rich-text-types | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:@fortawesome/react-fontawesome | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:@fortawesome/pro-solid-svg-icons | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:@fortawesome/fontawesome-svg-core | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai | |
| phantom-deps | phantom-dep:@fortawesome/pro-regular-svg-icons | AI (phantom-deps): Bundled component library; deps declared for consumer resolution, not direct imports in source. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 1.0.861 | 16 / 24 | |
| 1.0.856 | 16 / 24 | |
| 1.0.855 | 16 / 24 | |
| 1.0.850 | 16 / 24 | |
| 1.0.842 | 16 / 24 | |
| 1.0.744 | 16 / 24 | |
| 1.0.720 | 16 / 24 | |
| 1.0.708 | 16 / 24 | |
| 1.0.704 | 16 / 24 | |
| 1.0.672 | 16 / 24 | |
| 1.0.668 | 16 / 24 | |
| 1.0.661 | 16 / 24 | |
| 1.0.657 | 16 / 24 | |
| 1.0.655 | 16 / 24 | |
| 1.0.529 | 16 / 24 | |
| 1.0.527 | 16 / 24 | |
| 1.0.526 | 16 / 24 | |
| 1.0.525 | 16 / 24 | |
| 1.0.422 | 14 / 24 |
v1.0.856
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.855
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.850
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.744
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.720
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.708
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.704
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.672
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.668
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.661
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.657
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.655
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.529
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.527
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.526
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.525
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.422
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.