@magic-xpa/angular
This package is part of Magic xpa Web Application Framework. It is used to easily create modern business apps powered by Angular to provide a rich user experience and meet the increasingly complex enterprise business expectations for digital transformati
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file-transition:esm5/src/services/component-list.magic.service.js | AI (source-diff): Downlevel emit of same file; inline base64 source map only. Stable FP for this build pipeline. | ai | |
| source-diff | obfuscated-file:esm2015/src/services/spinner.service.js | AI (source-diff): Long line is an inline base64 sourceMappingURL from ng-packagr/tsickle; decoded to matching TS. Readable code. | ai | |
| source-diff | obfuscated-file:esm5/src/services/spinner.service.js | AI (source-diff): Downlevel emit of same file; long line is inline base64 source map, not obfuscation. | ai | |
| source-diff | obfuscated-file-transition:esm2015/src/services/component-list.magic.service.js | AI (source-diff): Readable tsickle output; >3000-char line is inline base64 source map decoded to matching TS source. | ai | |
| provenance | no-provenance | AI (provenance): Provenance missing but common; low risk given package maturity and ecosystem adoption. | ai | |
| dependencies | unvetted-dep:@maskito/angular | AI (dependencies): @maskito/angular is a legitimate, widely-used input masking library; stable dependency for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Commercial SDK with EULA license; sparse metadata is consistent across all versions of this package family. | ai | |
| phantom-deps | phantom-dep:@magic-xpa/angular-material-core | AI (phantom-deps): Same org scope; declared as a dependency even if not directly imported — stable false positive for this package. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 4.1202.0 | 8 / 0 | |
| 4.1201.1 | 8 / 0 | |
| 4.1201.0 | 8 / 0 | |
| 4.1200.0 | 8 / 0 | |
| 4.1101.2 | 8 / 0 | |
| 4.1101.1 | 8 / 0 | |
| 4.1101.0 | 8 / 0 | |
| 4.1100.0 | 8 / 0 | |
| 4.602.0 | 3 / 0 | |
| 4.601.1 | 3 / 0 | |
| 4.601.0 | 3 / 0 | |
| 4.600.0 | 3 / 0 | |
| 4.6.0 | 3 / 0 | |
| 4.5.1 | 3 / 0 | |
| 4.5.0 | 3 / 0 |
v4.1101.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1101.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1101.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1100.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.602.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.601.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.601.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.600.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.