@harness-engineering/dashboard
Local web dashboard for harness project health and roadmap visualization
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@tremor/react | AI (phantom-deps): UI component library bundled into client dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:zustand | AI (phantom-deps): State management lib consumed in bundled client code. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Peer of react; consumed via Vite bundling. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Used as remark plugin in config; not a direct import pattern. | ai | |
| phantom-deps | phantom-dep:lucide-react | AI (phantom-deps): Icon lib consumed via JSX bundling. | ai | |
| phantom-deps | phantom-dep:react-router | AI (phantom-deps): Consumed via JSX bundling in Vite build. | ai | |
| phantom-deps | phantom-dep:framer-motion | AI (phantom-deps): Animation lib consumed via JSX bundling. | ai | |
| phantom-deps | phantom-dep:react-markdown | AI (phantom-deps): Consumed via JSX bundling. | ai | |
| phantom-deps | phantom-dep:react-virtuoso | AI (phantom-deps): Consumed via JSX bundling. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/typography | AI (phantom-deps): Tailwind plugin referenced in config. | ai | |
| phantom-deps | phantom-dep:react-syntax-highlighter | AI (phantom-deps): Consumed via JSX bundling. | ai | |
| phantom-deps | phantom-dep:@harness-engineering/types | AI (phantom-deps): Same-org types package; used for type imports stripped at build. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): React is consumed via JSX/Vite bundling; not directly imported in dist output. | ai |
Versions (showing 26 of 26)
| Version | Deps | Published |
|---|---|---|
| 0.8.1 | 19 / 15 | |
| 0.8.0 | 19 / 15 | |
| 0.7.0 | 19 / 15 | |
| 0.6.7 | 19 / 15 | |
| 0.6.6 | 19 / 15 | |
| 0.6.5 | 19 / 15 | |
| 0.6.4 | 19 / 15 | |
| 0.6.3 | 19 / 15 | |
| 0.6.2 | 17 / 15 | |
| 0.6.1 | 17 / 15 | |
| 0.6.0 | 17 / 15 | |
| 0.5.2 | 17 / 15 | |
| 0.5.1 | 17 / 15 | |
| 0.5.0 | 17 / 15 | |
| 0.4.1 | 17 / 15 | |
| 0.4.0 | 17 / 15 | |
| 0.3.0 | 17 / 15 | |
| 0.2.2 | 16 / 15 | |
| 0.2.1 | 16 / 15 | |
| 0.2.0 | 16 / 15 | |
| 0.1.9 | 16 / 15 | |
| 0.1.7 | 16 / 15 | |
| 0.1.6 | 16 / 15 | |
| 0.1.5 | 16 / 15 | |
| 0.1.4 | 10 / 14 | |
| 0.1.2 | 10 / 14 |
v0.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.