← Home

@hmcts/media-viewer

2
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

timja-hmctstimjajenkins-reform-hmctsplayfair0319thomast1906hmctsnpm

Keywords

AngularPDFAnnotation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:mutable-div AI (dependencies): Recurring dependency in this established HMCTS package; no malicious indicators found. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a known Angular/TypeScript implicit runtime dependency; stable false positive for Angular libraries. ai
phantom-deps phantom-dep:socket.io-client AI (phantom-deps): Referenced in config files per analyzer note; not a direct import concern for this package. ai

Versions (showing 2 of 2)

Version Deps Published
4.2.18 6 / 0
4.2.16 6 / 0

v4.2.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.