@genesislcap/foundation-openfin
Genesis Foundation Openfin
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Consistent across all Genesis org packages; org-level build process does not emit Sigstore attestations. | ai | |
| phantom-deps | phantom-dep:@finos/fdc3 | AI (phantom-deps): Declared as peer/runtime dep for OpenFin FDC3 integration; not directly imported in source is expected for this adapter pattern. | ai | |
| phantom-deps | phantom-dep:@interopio/desktop | AI (phantom-deps): Optional interop SDK dependency; adapter pattern means it may not be directly imported in all code paths. | ai | |
| phantom-deps | phantom-dep:@openfin/workspace-platform | AI (phantom-deps): OpenFin workspace platform SDK; adapter pattern means indirect usage is expected. | ai | |
| phantom-deps | phantom-dep:rxjs | AI (phantom-deps): rxjs is a standard reactive dependency; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@genesislcap/foundation-logger | AI (phantom-deps): Same-org dependency; phantom detection is unreliable across monorepo boundaries. | ai |
Versions (showing 35 of 538)
| Version | Deps | Published |
|---|---|---|
| 14.232.1 | 11 / 9 | |
| 14.232.0 | 11 / 9 | |
| 14.231.0 | 11 / 9 | |
| 14.230.2 | 11 / 9 | |
| 14.230.1 | 11 / 9 | |
| 14.230.0 | 11 / 9 | |
| 14.229.0 | 11 / 9 | |
| 14.228.1 | 11 / 9 | |
| 14.228.0 | 11 / 9 | |
| 14.227.4 | 11 / 9 | |
| 14.227.3 | 11 / 9 | |
| 14.227.2 | 11 / 9 | |
| 14.227.1 | 11 / 9 | |
| 14.227.0 | 11 / 9 | |
| 14.226.1 | 11 / 9 | |
| 14.226.0 | 11 / 9 | |
| 14.225.3 | 11 / 9 | |
| 14.225.2 | 11 / 9 | |
| 14.225.1 | 11 / 9 | |
| 14.225.0 | 11 / 9 | |
| 14.224.4 | 11 / 9 | |
| 14.224.3 | 11 / 9 | |
| 14.224.2 | 11 / 9 | |
| 14.224.1 | 11 / 9 | |
| 14.224.0 | 11 / 9 | |
| 14.223.0 | 11 / 9 | |
| 14.222.0 | 11 / 9 | |
| 14.221.0 | 11 / 9 | |
| 14.220.0 | 11 / 9 | |
| 14.219.2 | 11 / 9 | |
| 14.219.1 | 11 / 9 | |
| 14.219.0 | 11 / 9 | |
| 14.218.2 | 11 / 9 | |
| 14.218.1 | 11 / 9 | |
| 14.218.0 | 13 / 9 |
v14.232.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.232.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.231.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.230.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.230.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.230.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.229.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.228.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.228.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.227.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.227.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.227.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.227.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.227.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.226.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.226.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.225.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.225.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.225.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.225.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.224.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.224.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.224.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.224.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.224.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.223.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.222.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.221.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.220.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.219.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.219.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.219.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.218.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.218.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.218.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.