@flarehr/salpac-finops-admin
Salpac FinOps Admin
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Bundled Preact web component; deps declared for consumers, not directly imported in analyzed source. | ai | |
| phantom-deps | phantom-dep:@emotion/css | AI (phantom-deps): Emotion CSS-in-JS used via babel macros/config, not direct import; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/cache | AI (phantom-deps): Same as @emotion/css — macro-based usage pattern. | ai | |
| phantom-deps | phantom-dep:@emotion/react | AI (phantom-deps): Same as @emotion/css — macro-based usage pattern. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Same as @emotion/css — macro-based usage pattern. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Peer dep for consumers of the web component; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:@heroicons/react | AI (phantom-deps): Icon library used via JSX transform; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): UI component lib used via JSX; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Used in build config/entry point; stable FP for this package. | ai |
Versions (showing 30 of 441)
| Version | Deps | Published |
|---|---|---|
| 1.0.687 | 9 / 32 | |
| 1.0.686 | 9 / 32 | |
| 1.0.685 | 9 / 32 | |
| 1.0.684 | 9 / 32 | |
| 1.0.683 | 9 / 32 | |
| 1.0.682 | 9 / 32 | |
| 1.0.681 | 9 / 32 | |
| 1.0.680 | 9 / 32 | |
| 1.0.679 | 9 / 32 | |
| 1.0.678 | 9 / 32 | |
| 1.0.677 | 9 / 32 | |
| 1.0.676 | 9 / 32 | |
| 1.0.675 | 9 / 32 | |
| 1.0.674 | 9 / 32 | |
| 1.0.673 | 9 / 32 | |
| 1.0.672 | 9 / 32 | |
| 1.0.671 | 9 / 32 | |
| 1.0.670 | 9 / 32 | |
| 1.0.669 | 9 / 32 | |
| 1.0.668 | 9 / 32 | |
| 1.0.667 | 9 / 32 | |
| 1.0.666 | 9 / 32 | |
| 1.0.665 | 9 / 32 | |
| 1.0.664 | 9 / 32 | |
| 1.0.663 | 9 / 32 | |
| 1.0.662 | 9 / 32 | |
| 1.0.661 | 9 / 32 | |
| 1.0.660 | 9 / 32 | |
| 1.0.659 | 9 / 32 | |
| 1.0.658 | 9 / 32 |
v1.0.687
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.686
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.685
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.684
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.683
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.682
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.681
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.680
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.679
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.678
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.677
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.676
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.675
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.674
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.673
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.672
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.671
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.670
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.669
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.668
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.667
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.666
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.665
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.664
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.663
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.662
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.661
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.660
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.659
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.658
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.