@fundamental-ngx/core
Fundamental Library for Angular - core
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | regressed-provenance | AI (provenance): Manual publish by known maintainer name, not an account compromise pattern. | ai | |
| source-diff | obfuscated-file:types/fundamental-ngx-core-date-picker.d.ts | AI (source-diff): Angular compiler-generated .d.ts with long metadata lines; not obfuscation. Stable pattern for this Angular library. | ai | |
| source-diff | obfuscated-file:types/fundamental-ngx-core-datetime-picker.d.ts | AI (source-diff): Angular compiler-generated .d.ts with long metadata lines; not obfuscation. Stable pattern for this Angular library. | ai | |
| source-diff | obfuscated-file:datetime-picker/index.d.ts | AI (source-diff): Angular compiler-generated .d.ts files have long lines due to type concatenation; not obfuscation. | ai | |
| source-diff | obfuscated-file:date-picker/index.d.ts | AI (source-diff): Angular compiler-generated .d.ts files have long lines due to type concatenation; not obfuscation. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Established SAP Angular component library; name similarity to 'cors' is purely coincidental. | ai | |
| phantom-deps | phantom-dep:focus-trap | AI (phantom-deps): Same rationale — bundled Angular library; focus-trap usage may not surface as a direct import at the config level. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): Angular library with fesm2022 bundles; lodash-es may be tree-shaken into bundles without direct top-level imports. | ai |
Versions (showing 47 of 47)
| Version | Deps | Published |
|---|---|---|
| 0.64.0 | 5 / 0 | |
| 0.63.1 | 5 / 0 | |
| 0.63.0 | 5 / 0 | |
| 0.62.4 | 5 / 0 | |
| 0.62.3 | 5 / 0 | |
| 0.62.2 | 5 / 0 | |
| 0.62.1 | 5 / 0 | |
| 0.62.0 | 5 / 0 | |
| 0.61.7 | 5 / 0 | |
| 0.61.6 | 5 / 0 | |
| 0.61.5 | 5 / 0 | |
| 0.61.4 | 5 / 0 | |
| 0.61.3 | 5 / 0 | |
| 0.61.2 | 5 / 0 | |
| 0.61.1 | 5 / 0 | |
| 0.61.0 | 5 / 0 | |
| 0.60.3 | 5 / 0 | |
| 0.60.2 | 5 / 0 | |
| 0.60.1 | 5 / 0 | |
| 0.60.0 | 5 / 0 | |
| 0.59.3 | 5 / 0 | |
| 0.59.2 | 5 / 0 | |
| 0.59.1 | 5 / 0 | |
| 0.59.0 | 5 / 0 | |
| 0.58.10 | 5 / 0 | |
| 0.58.9 | 5 / 0 | |
| 0.58.8 | 5 / 0 | |
| 0.58.7 | 5 / 0 | |
| 0.58.6 | 5 / 0 | |
| 0.58.5 | 5 / 0 | |
| 0.58.4 | 5 / 0 | |
| 0.58.3 | 5 / 0 | |
| 0.58.2 | 5 / 0 | |
| 0.58.1 | 5 / 0 | |
| 0.58.0 | 5 / 0 | |
| 0.57.12 | 5 / 0 | |
| 0.57.11 | 5 / 0 | |
| 0.57.10 | 5 / 0 | |
| 0.57.9 | 5 / 0 | |
| 0.57.8 | 5 / 0 | |
| 0.57.7 | 5 / 0 | |
| 0.57.6 | 5 / 0 | |
| 0.57.5 | 5 / 0 | |
| 0.57.4 | 5 / 0 | |
| 0.56.9 | 5 / 0 | |
| 0.56.8 | 5 / 0 | |
| 0.55.10 | 5 / 0 |
v0.64.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.60.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.60.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.60.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.60.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (fundamental-ui) on 2026-01-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.57.12
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (fundamental-ui) than the most recent previously approved version (GitHub Actions) on 2026-03-17, but fundamental-ui is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.57.11
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (fundamental-ui) than the most recent previously approved version (GitHub Actions) on 2026-03-06, but fundamental-ui is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.57.10
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (fundamental-ui) than the most recent previously approved version (GitHub Actions) on 2026-02-20, but fundamental-ui is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.57.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.57.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.56.9
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (fundamental-ui) than the most recent previously approved version (GitHub Actions) on 2026-02-20, but fundamental-ui is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.56.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.55.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.