@flarehr/superhero-benefits-onboarding
Flare Superhero Benefits Onboarding Component
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Bundled component; deps consumed at build time and shipped in dist/, not imported directly by static analysis. | ai | |
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:jwt-decode | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@heroicons/react | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai |
Versions (showing 51 of 338)
| Version | Deps | Published |
|---|---|---|
| 2.17.23 | 7 / 25 | |
| 2.16.22 | 7 / 25 | |
| 2.15.21 | 7 / 25 | |
| 2.14.20 | 7 / 25 | |
| 2.13.18 | 7 / 25 | |
| 0.2.1207 | 7 / 25 | |
| 0.2.1206 | 7 / 25 | |
| 0.2.1205 | 7 / 25 | |
| 0.2.1204 | 7 / 25 | |
| 0.2.1203 | 7 / 25 | |
| 0.2.1202 | 7 / 25 | |
| 0.2.1201 | 7 / 25 | |
| 0.2.1200 | 7 / 25 | |
| 0.2.1199 | 7 / 25 | |
| 0.2.1198 | 7 / 25 | |
| 0.2.1197 | 7 / 25 | |
| 0.2.1196 | 7 / 25 | |
| 0.2.1195 | 7 / 25 | |
| 0.2.1194 | 7 / 25 | |
| 0.2.1193 | 7 / 25 | |
| 0.2.1192 | 7 / 25 | |
| 0.2.1191 | 7 / 25 | |
| 0.2.1190 | 7 / 25 | |
| 0.2.1189 | 7 / 25 | |
| 0.2.1188 | 7 / 25 | |
| 0.2.1187 | 7 / 25 | |
| 0.2.1186 | 7 / 25 | |
| 0.2.1185 | 7 / 25 | |
| 0.2.1184 | 7 / 25 | |
| 0.2.1183 | 7 / 25 | |
| 0.2.1182 | 7 / 25 | |
| 0.2.1181 | 7 / 25 | |
| 0.2.1180 | 7 / 25 | |
| 0.2.1179 | 7 / 25 | |
| 0.2.1178 | 7 / 25 | |
| 0.2.1176 | 7 / 25 | |
| 0.2.1174 | 7 / 25 | |
| 0.2.1173 | 7 / 25 | |
| 0.2.1172 | 7 / 25 | |
| 0.2.1171 | 7 / 25 | |
| 0.2.1170 | 7 / 25 | |
| 0.2.1169 | 7 / 25 | |
| 0.2.1168 | 7 / 25 | |
| 0.2.1167 | 7 / 25 | |
| 0.2.1166 | 7 / 25 | |
| 0.2.1165 | 7 / 25 | |
| 0.2.1163 | 7 / 25 | |
| 0.2.1162 | 7 / 25 | |
| 0.2.1161 | 7 / 25 | |
| 0.2.1160 | 7 / 25 | |
| 0.2.1159 | 7 / 25 |
v2.17.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.14.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1207
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1206
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1205
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1204
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1203
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1202
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1201
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1200
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1199
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1198
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1197
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1196
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1195
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1194
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1193
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1192
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1191
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1190
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1189
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1188
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1187
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1186
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1185
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1184
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1183
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1182
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1181
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1180
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1179
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1178
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1176
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1174
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1173
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1172
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1171
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1170
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1169
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1168
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1167
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1166
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1165
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1163
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1162
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1161
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1160
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1159
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.