@huntsman-cancer-institute/reporting-framework
This library was generated with [Angular CLI](https://github.com/angular/angular-cli) version 12.2.0.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:src/report.module.ngfactory.js | AI (source-diff): Angular AOT compiler output; long lines are generated factory code, not obfuscation. | ai | |
| source-diff | obfuscated-file:fesm2015/huntsman-cancer-institute-reporting-framework.js | AI (source-diff): Standard Angular Ivy compiled bundle with long inline template strings; not obfuscation. | ai | |
| source-diff | obfuscated-file:fesm5/huntsman-cancer-institute-reporting-framework.js | AI (source-diff): Standard Angular Ivy compiled bundle; long lines are inline templates, not obfuscation. | ai | |
| source-diff | obfuscated-file:esm2015/parameter/parameter.component.js | AI (source-diff): Angular Ivy compiled component with inline template; not obfuscation. | ai | |
| source-diff | obfuscated-file:esm5/parameter/parameter.component.js | AI (source-diff): Angular Ivy compiled component with inline template; not obfuscation. | ai | |
| source-diff | obfuscated-file:esm2015/datepicker/report-datepicker.component.js | AI (source-diff): Angular Ivy compiled component with inline template; not obfuscation. | ai | |
| source-diff | obfuscated-file:esm5/datepicker/report-datepicker.component.js | AI (source-diff): Angular Ivy compiled component with inline template; not obfuscation. | ai | |
| source-diff | obfuscated-file:esm2015/resizable-divider/resizable-section-divider.component.js | AI (source-diff): Angular Ivy compiled component; long lines are inline templates, not obfuscation. | ai | |
| source-diff | obfuscated-file:esm5/resizable-divider/resizable-section-divider.component.js | AI (source-diff): Angular Ivy compiled component; long lines are inline templates, not obfuscation. | ai | |
| source-diff | obfuscated-file:esm2015/report.module.js | AI (source-diff): Angular Ivy compiled NgModule; long lines are metadata declarations, not obfuscation. | ai | |
| source-diff | obfuscated-file:esm5/report.module.js | AI (source-diff): Angular Ivy compiled NgModule; long lines are metadata declarations, not obfuscation. | ai | |
| source-diff | obfuscated-file:esm2015/reporting-framework.component.js | AI (source-diff): Angular Ivy compiled component; long lines are inline templates, not obfuscation. | ai | |
| source-diff | obfuscated-file:esm5/reporting-framework.component.js | AI (source-diff): Angular Ivy compiled component; long lines are inline templates, not obfuscation. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard Angular compiler implicit dep; not directly imported but always required at runtime. | ai | |
| phantom-deps | phantom-dep:@huntsman-cancer-institute/dictionary-service | AI (phantom-deps): Same-org scoped dep; declared in dependencies and used transitively within the org's library ecosystem. | ai |
Versions (showing 51 of 78)
| Version | Deps | Published |
|---|---|---|
| 17.24.0 | 3 / 0 | |
| 17.23.8 | 3 / 0 | |
| 17.23.7 | 3 / 0 | |
| 17.23.6 | 3 / 0 | |
| 17.23.5 | 3 / 0 | |
| 17.23.4 | 3 / 0 | |
| 17.23.3 | 3 / 0 | |
| 17.23.2 | 3 / 0 | |
| 17.23.1 | 3 / 0 | |
| 17.23.0 | 3 / 0 | |
| 17.22.0 | 3 / 0 | |
| 17.21.1 | 3 / 0 | |
| 17.21.0 | 3 / 0 | |
| 17.20.8 | 3 / 0 | |
| 17.20.7 | 3 / 0 | |
| 17.20.6 | 3 / 0 | |
| 17.20.5 | 3 / 0 | |
| 17.20.0 | 3 / 0 | |
| 17.19.0 | 3 / 0 | |
| 17.18.4 | 3 / 0 | |
| 17.18.3 | 3 / 0 | |
| 17.18.2 | 3 / 0 | |
| 17.18.1 | 3 / 0 | |
| 17.18.0 | 3 / 0 | |
| 17.17.6 | 3 / 0 | |
| 17.17.5 | 3 / 0 | |
| 17.17.4 | 3 / 0 | |
| 17.17.3 | 3 / 0 | |
| 17.17.2 | 3 / 0 | |
| 17.17.0 | 3 / 0 | |
| 17.16.1 | 3 / 0 | |
| 17.16.0 | 3 / 0 | |
| 17.15.1 | 3 / 0 | |
| 17.15.0 | 3 / 0 | |
| 17.14.6 | 3 / 0 | |
| 17.14.5 | 3 / 0 | |
| 17.14.4 | 3 / 0 | |
| 17.14.3 | 3 / 0 | |
| 17.14.2 | 3 / 0 | |
| 17.14.1 | 3 / 0 | |
| 17.14.0 | 3 / 0 | |
| 17.13.0 | 3 / 0 | |
| 17.12.0 | 3 / 0 | |
| 17.11.7 | 3 / 0 | |
| 17.11.6 | 3 / 0 | |
| 17.11.5 | 3 / 0 | |
| 17.11.4 | 3 / 0 | |
| 17.11.3 | 3 / 0 | |
| 17.11.1 | 3 / 0 | |
| 17.11.0 | 3 / 0 | |
| 17.10.4 | 3 / 0 |
v17.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.23.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.23.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v17.23.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.23.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.23.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.23.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.23.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.23.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.21.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.21.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v17.20.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v17.20.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v17.20.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.20.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.20.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.18.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.18.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.18.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.18.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.17.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.17.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.17.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.17.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.17.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.16.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.15.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.14.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.14.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.14.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.14.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.14.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.14.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.13.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v17.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v17.11.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v17.11.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.11.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.11.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.11.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.11.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.10.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.