@fundamental-ngx/platform
Fundamental Library for Angular - platform
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:types/fundamental-ngx-platform-form.d.ts | AI (source-diff): Angular-generated .d.ts files with long import lines; not obfuscation. | ai | |
| source-diff | obfuscated-file:types/fundamental-ngx-platform-search-field.d.ts | AI (source-diff): Angular-generated .d.ts files with long import lines; not obfuscation. | ai | |
| source-diff | obfuscated-file:types/fundamental-ngx-platform-table.d.ts | AI (source-diff): Angular-generated .d.ts files with long import lines; not obfuscation. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): lodash-es referenced in config files; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:form/index.d.ts | AI (source-diff): Angular-generated .d.ts declaration file with long import lines; not obfuscated code. | ai | |
| phantom-deps | phantom-dep:focus-trap | AI (phantom-deps): focus-trap referenced in config files; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:table/index.d.ts | AI (source-diff): Angular-generated .d.ts declaration file with long import lines; not obfuscated code. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard Angular/TypeScript runtime implicit dependency. | ai |
Versions (showing 47 of 47)
| Version | Deps | Published |
|---|---|---|
| 0.64.0 | 4 / 0 | |
| 0.63.1 | 4 / 0 | |
| 0.63.0 | 4 / 0 | |
| 0.62.4 | 4 / 0 | |
| 0.62.3 | 4 / 0 | |
| 0.62.2 | 4 / 0 | |
| 0.62.1 | 4 / 0 | |
| 0.62.0 | 4 / 0 | |
| 0.61.7 | 4 / 0 | |
| 0.61.6 | 4 / 0 | |
| 0.61.5 | 4 / 0 | |
| 0.61.4 | 4 / 0 | |
| 0.61.3 | 4 / 0 | |
| 0.61.2 | 4 / 0 | |
| 0.61.1 | 4 / 0 | |
| 0.61.0 | 4 / 0 | |
| 0.60.3 | 4 / 0 | |
| 0.60.2 | 4 / 0 | |
| 0.60.1 | 4 / 0 | |
| 0.60.0 | 4 / 0 | |
| 0.59.3 | 4 / 0 | |
| 0.59.2 | 4 / 0 | |
| 0.59.1 | 4 / 0 | |
| 0.59.0 | 4 / 0 | |
| 0.58.10 | 4 / 0 | |
| 0.58.9 | 4 / 0 | |
| 0.58.8 | 4 / 0 | |
| 0.58.7 | 4 / 0 | |
| 0.58.6 | 4 / 0 | |
| 0.58.5 | 4 / 0 | |
| 0.58.4 | 4 / 0 | |
| 0.58.3 | 4 / 0 | |
| 0.58.2 | 4 / 0 | |
| 0.58.1 | 4 / 0 | |
| 0.58.0 | 4 / 0 | |
| 0.57.11 | 4 / 0 | |
| 0.57.9 | 4 / 0 | |
| 0.57.8 | 4 / 0 | |
| 0.57.7 | 4 / 0 | |
| 0.57.6 | 4 / 0 | |
| 0.57.5 | 4 / 0 | |
| 0.57.4 | 4 / 0 | |
| 0.56.8 | 4 / 0 | |
| 0.55.10 | 4 / 0 | |
| 0.11.2 | 2 / 0 | |
| 0.11.1 | 2 / 0 | |
| 0.11.0 | 2 / 0 |
v0.64.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.61.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.60.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.60.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.60.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.60.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (fundamental-ui) on 2026-01-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.58.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (fundamental-ui) on 2026-01-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.57.11
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (fundamental-ui) than the most recent previously approved version (GitHub Actions) on 2026-03-06, but fundamental-ui is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.57.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.57.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.56.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.55.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.