@gooddata/sdk-ui-geo
GoodData.UI SDK - Geo Charts
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@gooddata/number-formatter | AI (dependencies): First-party GoodData dependency; stable pattern across this package's many versions. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Active org with frequent team rotation; consistent with legitimate maintainer management. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same org rotation pattern; no evidence of hostile takeover. | ai | |
| provenance | no-provenance | AI (provenance): Large established GoodData SDK monorepo; provenance not enabled but publisher track record is strong. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Active SDK monorepo; large file additions are routine across version bumps for this package. | ai | |
| phantom-deps | phantom-dep:@gooddata/sdk-ui-kit | AI (phantom-deps): Same-org monorepo dep; may be used indirectly via re-exports. Stable false positive. | ai | |
| email-domain | unclaimed-email:rodri360.com | AI (email-domain): Package published by gooddata-ci org bot; individual maintainer email domain risk is low for this established corporate SDK. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit TypeScript runtime dep; stable false positive for this package. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 11.40.0 | 17 / 44 | |
| 11.39.0 | 17 / 44 | |
| 11.36.0 | 17 / 44 | |
| 11.32.0 | 17 / 44 | |
| 11.31.0 | 17 / 44 | |
| 11.30.0 | 17 / 44 | |
| 11.28.0 | 17 / 44 | |
| 11.27.0 | 17 / 44 | |
| 11.26.0 | 17 / 44 | |
| 11.25.0 | 17 / 44 | |
| 11.24.0 | 17 / 44 | |
| 11.22.0 | 17 / 44 | |
| 11.18.0 | 17 / 45 | |
| 11.16.0 | 17 / 43 | |
| 11.12.0 | 17 / 43 | |
| 11.11.0 | 17 / 43 | |
| 11.9.0 | 17 / 42 |
v11.40.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.39.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.30.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.28.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.27.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.24.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.16.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.12.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.11.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.9.0
2 findingsMaintainer email '[email protected]' uses domain 'rodri360.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.