@flarehr/salpac-cars-calculator
Flare Cars Calculator
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/energy-flex-cars-calculator.js | AI (source-diff): Standard Vite/Preact minified bundle output; consistent with multi-config build pipeline. | ai | |
| source-diff | net-exec-file:dist/energy-flex-cars-calculator.js | AI (source-diff): Network calls and dynamic patterns are Preact vdom internals in minified bundle, not malware. | ai | |
| source-diff | obfuscated-file:dist/byd-cars-calculator.js | AI (source-diff): Standard Vite/Preact minified bundle output; consistent across all versions of this package. | ai | |
| source-diff | net-exec-file:dist/byd-cars-calculator.js | AI (source-diff): Network calls and dynamic patterns are part of Preact's vdom runtime, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/flare-cars-calculator.js | AI (source-diff): Standard Vite/Preact minified bundle output; consistent across all versions of this package. | ai | |
| source-diff | net-exec-file:dist/flare-cars-calculator.js | AI (source-diff): Network calls and dynamic patterns are part of Preact's vdom runtime, not dropper behavior. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@heroicons/react | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Bundled output package; deps declared in package.json but consumed via build artifacts, not direct imports. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-highlight-words | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:smoothscroll-polyfill | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/css | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/cache | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/react | AI (phantom-deps): Same bundled output pattern; stable false positive for this package. | ai |
Versions (showing 100 of 342)
| Version | Deps | Published |
|---|---|---|
| 1.0.1215 | 13 / 43 | |
| 1.0.1214 | 13 / 43 | |
| 1.0.1213 | 13 / 43 | |
| 1.0.1212 | 13 / 43 | |
| 1.0.1211 | 13 / 43 | |
| 1.0.1210 | 13 / 43 | |
| 1.0.1209 | 13 / 43 | |
| 1.0.1208 | 13 / 43 | |
| 1.0.1207 | 13 / 43 | |
| 1.0.1206 | 13 / 43 | |
| 1.0.1205 | 13 / 43 | |
| 1.0.1204 | 13 / 43 | |
| 1.0.1203 | 13 / 43 | |
| 1.0.1202 | 13 / 43 | |
| 1.0.1201 | 13 / 43 | |
| 1.0.1200 | 13 / 43 | |
| 1.0.1199 | 13 / 43 | |
| 1.0.1198 | 13 / 43 | |
| 1.0.1197 | 13 / 43 | |
| 1.0.1196 | 13 / 43 | |
| 1.0.1195 | 13 / 43 | |
| 1.0.1194 | 13 / 43 | |
| 1.0.1193 | 13 / 43 | |
| 1.0.1192 | 13 / 43 | |
| 1.0.1191 | 13 / 43 | |
| 1.0.1190 | 13 / 43 | |
| 1.0.1189 | 13 / 43 | |
| 1.0.1188 | 13 / 43 | |
| 1.0.1187 | 13 / 43 | |
| 1.0.1186 | 13 / 43 | |
| 1.0.1185 | 13 / 43 | |
| 1.0.1184 | 13 / 43 | |
| 1.0.1183 | 13 / 43 | |
| 1.0.1182 | 13 / 43 | |
| 1.0.1181 | 13 / 43 | |
| 1.0.1180 | 13 / 43 | |
| 1.0.1179 | 13 / 43 | |
| 1.0.1178 | 13 / 43 | |
| 1.0.1177 | 13 / 43 | |
| 1.0.1176 | 13 / 43 | |
| 1.0.1175 | 13 / 43 | |
| 1.0.1173 | 13 / 43 | |
| 1.0.1172 | 13 / 43 | |
| 1.0.1171 | 13 / 43 | |
| 1.0.1170 | 13 / 43 | |
| 1.0.1169 | 13 / 43 | |
| 1.0.1168 | 13 / 43 | |
| 1.0.1167 | 13 / 43 | |
| 1.0.1166 | 13 / 43 | |
| 1.0.1165 | 13 / 43 | |
| 1.0.1164 | 13 / 43 | |
| 1.0.1163 | 13 / 43 | |
| 1.0.1162 | 13 / 43 | |
| 1.0.1161 | 13 / 43 | |
| 1.0.1160 | 13 / 43 | |
| 1.0.1159 | 13 / 43 | |
| 1.0.1158 | 13 / 43 | |
| 1.0.1157 | 13 / 43 | |
| 1.0.1156 | 13 / 43 | |
| 1.0.1155 | 13 / 43 | |
| 1.0.1154 | 13 / 43 | |
| 1.0.1153 | 13 / 43 | |
| 1.0.1152 | 13 / 43 | |
| 1.0.1151 | 13 / 43 | |
| 1.0.1150 | 13 / 43 | |
| 1.0.1149 | 13 / 43 | |
| 1.0.1148 | 13 / 43 | |
| 1.0.1147 | 13 / 43 | |
| 1.0.1146 | 13 / 43 | |
| 1.0.1145 | 13 / 43 | |
| 1.0.1144 | 13 / 43 | |
| 1.0.1143 | 13 / 43 | |
| 1.0.1142 | 13 / 43 | |
| 1.0.1141 | 13 / 43 | |
| 1.0.1140 | 13 / 43 | |
| 1.0.1139 | 13 / 43 | |
| 1.0.1138 | 13 / 43 | |
| 1.0.1137 | 13 / 43 | |
| 1.0.1136 | 13 / 43 | |
| 1.0.1135 | 13 / 43 | |
| 1.0.1134 | 13 / 43 | |
| 1.0.1133 | 13 / 43 | |
| 1.0.1132 | 13 / 43 | |
| 1.0.1131 | 13 / 43 | |
| 1.0.1130 | 13 / 43 | |
| 1.0.1129 | 13 / 43 | |
| 1.0.1128 | 13 / 43 | |
| 1.0.1127 | 13 / 43 | |
| 1.0.1126 | 13 / 43 | |
| 1.0.1125 | 13 / 43 | |
| 1.0.1124 | 13 / 43 | |
| 1.0.1123 | 13 / 43 | |
| 1.0.1122 | 13 / 43 | |
| 1.0.1121 | 13 / 43 | |
| 1.0.1120 | 13 / 43 | |
| 1.0.1119 | 13 / 43 | |
| 1.0.1118 | 13 / 43 | |
| 1.0.1117 | 13 / 43 | |
| 1.0.1116 | 13 / 43 | |
| 1.0.1115 | 13 / 43 |
v1.0.1215
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1214
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1213
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1212
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1211
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1210
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1209
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1208
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1207
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1206
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1205
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1204
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1203
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1202
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1201
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1200
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1199
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1198
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1197
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1196
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1195
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1194
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1193
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1192
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1191
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1190
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1189
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1188
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1187
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1186
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1185
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1184
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1183
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1182
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1181
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1180
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1179
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1178
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1177
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1176
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1175
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1173
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1172
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1171
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1170
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1169
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1168
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1167
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1166
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1165
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1164
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1163
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1162
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1161
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1160
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1159
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1158
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1157
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1156
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1155
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1154
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1153
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1152
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1151
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1150
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1149
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1148
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1147
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1146
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1145
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1144
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1143
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1142
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1141
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1140
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1139
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1138
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1137
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1136
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1135
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1134
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1133
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1132
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1131
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1130
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1129
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1128
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1127
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1126
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1125
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1124
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1123
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1122
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1121
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1120
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1119
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1118
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1117
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1116
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1115
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.