@harnessio/react-ng-manager-client
Harness React NG manager client - NG manager APIs integrated with react hooks
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Generated API client; large file counts expected from codegen tooling. | ai | |
| dependencies | unvetted-dep:@harnessio/fetcher | AI (dependencies): First-party Harness package, consistent with org's client ecosystem. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): Used by generated react-query hooks in dist build output. | ai | |
| phantom-deps | phantom-dep:qs | AI (phantom-deps): Used by generated fetcher/client code in dist build, not scannable source. | ai | |
| provenance | missing-githead | AI (provenance): Trusted long-standing publisher; CI environment variance, no behavioral signal. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Harness-affiliated maintainers added, consistent with org team rotation. | ai | |
| phantom-deps | phantom-dep:@types/qs | AI (phantom-deps): Types package used by convention, not directly imported. | ai |
Versions (showing 51 of 84)
| Version | Deps | Published |
|---|---|---|
| 1.54.0 | 0 / 0 | |
| 1.53.0 | 0 / 0 | |
| 1.52.0 | 0 / 0 | |
| 1.51.0 | 0 / 0 | |
| 1.50.0 | 0 / 0 | |
| 1.49.0 | 0 / 0 | |
| 1.48.0 | 0 / 0 | |
| 1.47.0 | 0 / 0 | |
| 1.46.1 | 0 / 0 | |
| 1.46.0 | 0 / 0 | |
| 1.45.0 | 0 / 0 | |
| 1.44.2 | 0 / 0 | |
| 1.44.1 | 0 / 0 | |
| 1.44.0 | 0 / 0 | |
| 1.43.0 | 0 / 0 | |
| 1.42.0 | 0 / 0 | |
| 1.41.0 | 0 / 0 | |
| 1.40.0 | 0 / 0 | |
| 1.39.0 | 0 / 0 | |
| 1.38.0 | 0 / 0 | |
| 1.37.0 | 0 / 0 | |
| 1.36.1 | 0 / 0 | |
| 1.36.0 | 0 / 0 | |
| 1.35.1 | 0 / 0 | |
| 1.35.0 | 0 / 0 | |
| 1.34.0 | 0 / 0 | |
| 1.33.0 | 0 / 0 | |
| 1.32.0 | 0 / 0 | |
| 1.31.2 | 0 / 0 | |
| 1.31.1 | 0 / 0 | |
| 1.31.0 | 0 / 0 | |
| 1.30.5 | 0 / 0 | |
| 1.30.4 | 0 / 0 | |
| 1.30.1 | 0 / 0 | |
| 1.29.0 | 0 / 0 | |
| 1.28.0 | 0 / 0 | |
| 1.27.0 | 0 / 0 | |
| 1.26.1 | 0 / 0 | |
| 1.26.0 | 0 / 0 | |
| 1.25.0 | 0 / 0 | |
| 1.24.0 | 0 / 0 | |
| 1.23.0 | 0 / 0 | |
| 1.21.0 | 0 / 0 | |
| 1.20.0 | 0 / 0 | |
| 1.19.8 | 0 / 0 | |
| 1.19.7 | 0 / 0 | |
| 1.19.6 | 0 / 0 | |
| 1.19.5 | 0 / 0 | |
| 1.19.4 | 0 / 0 | |
| 1.19.3 | 0 / 0 | |
| 1.19.2 | 0 / 0 |
v1.54.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.52.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.39.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.37.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.35.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.35.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.34.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.33.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.32.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.31.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mayankvermaharness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mayankvermaharness) than the most recent previously approved version (sunnykesh-harness) on 2024-10-18, but mayankvermaharness is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.29.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.26.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.21.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.20.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: sunnykesh-harness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.8
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: sunnykesh-harness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: sunnykesh-harness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: sunnykesh-harness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: sunnykesh-harness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: sunnykesh-harness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: sunnykesh-harness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: sunnykesh-harness.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.