@microsoft/teams-js
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Standard minified dist tree for the official Teams SDK. | ai | |
| source-diff | obfuscated-file:dist/esm/packages/teams-js/src/internal/appHelpers.js | AI (source-diff): Minified rollup ESM build output; benign. | ai | |
| source-diff | obfuscated-file:dist/esm/packages/teams-js/src/public/app/app.js | AI (source-diff): Minified rollup ESM build output, not obfuscation; stable for this build pipeline. | ai | |
| source-diff | obfuscated-file:dist/esm/packages/teams-js/src/internal/communication.js | AI (source-diff): Minified ESM build output. | ai | |
| source-diff | obfuscated-file:dist/esm/packages/teams-js/src/public/dialog.js | AI (source-diff): Minified ESM build output. | ai | |
| source-diff | obfuscated-file:dist/esm/packages/teams-js/src/public/app.js | AI (source-diff): Rollup-minified ESM dist output, not obfuscation; stable for this build pipeline. | ai | |
| source-diff | obfuscated-file:dist/esm/packages/teams-js/src/public/authentication.js | AI (source-diff): Minified ESM build output. | ai | |
| source-diff | obfuscated-file:dist/esm/packages/teams-js/src/internal/handlers.js | AI (source-diff): Minified ESM build output. | ai | |
| phantom-deps | phantom-dep:debug | AI (phantom-deps): debug referenced in config, standard transitive/logging dep. | ai | |
| provenance | no-provenance | AI (provenance): Established MS package; missing provenance not a risk here. | ai | |
| source-diff | obfuscated-file:dist/esm/packages/teams-js/src/private/externalAppAuthentication.js | AI (source-diff): Minified ESM build output. | ai | |
| source-diff | obfuscated-file:dist/esm/packages/teams-js/src/private/files.js | AI (source-diff): Minified ESM build output. | ai | |
| source-diff | obfuscated-file:dist/esm/packages/teams-js/src/public/shortcutRelay.js | AI (source-diff): Standard rollup ESM bundle output; minified but readable logic, consistent with this package's build process. | ai | |
| npm-metadata | url-dep:eslint-plugin-recommend-no-namespaces | AI (npm-metadata): Local file: path in devDependencies only; not included in published package files. Stable pattern for this monorepo package. | ai | |
| phantom-deps | phantom-dep:base64-js | AI (phantom-deps): base64-js is a declared runtime dependency; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 37 of 37)
| Version | Deps | Published |
|---|---|---|
| 2.54.0 | 2 / 2 | |
| 2.53.1 | 2 / 2 | |
| 2.53.0 | 2 / 2 | |
| 2.52.0 | 2 / 2 | |
| 2.51.0 | 2 / 2 | |
| 2.50.0 | 2 / 2 | |
| 2.49.0 | 2 / 2 | |
| 2.48.1 | 2 / 2 | |
| 2.48.0 | 2 / 2 | |
| 2.47.2 | 2 / 2 | |
| 2.47.1 | 2 / 2 | |
| 2.47.0 | 2 / 2 | |
| 2.46.0 | 2 / 2 | |
| 2.45.0 | 2 / 2 | |
| 2.44.0 | 2 / 2 | |
| 2.43.0 | 2 / 2 | |
| 2.42.0 | 2 / 2 | |
| 2.41.0 | 2 / 2 | |
| 2.40.0 | 2 / 2 | |
| 2.39.1 | 2 / 2 | |
| 2.39.0 | 2 / 2 | |
| 2.38.0 | 2 / 2 | |
| 2.37.0 | 2 / 2 | |
| 2.36.0 | 2 / 2 | |
| 2.35.0 | 2 / 2 | |
| 2.34.0 | 2 / 2 | |
| 2.33.0 | 2 / 1 | |
| 2.32.0 | 2 / 1 | |
| 2.31.1 | 2 / 1 | |
| 2.31.0 | 2 / 1 | |
| 2.30.0 | 2 / 1 | |
| 2.29.0 | 2 / 1 | |
| 2.28.0 | 2 / 1 | |
| 2.27.0 | 2 / 1 | |
| 2.26.0 | 2 / 1 | |
| 2.25.0 | 2 / 1 | |
| 2.24.0 | 2 / 1 |
v2.54.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.53.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.37.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.36.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.35.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.34.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.33.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.31.1
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.31.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.