@ministryofjustice/hmpps-connect-dps-components
A package to allow the inclusion of connect DPS micro frontend components within DPS applications
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): Framework-scoped type package; not directly imported by convention. | ai | |
| phantom-deps | phantom-dep:@types/nunjucks | AI (phantom-deps): Type-only package loaded by convention, not directly imported. | ai | |
| phantom-deps | phantom-dep:superagent | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ministryofjustice/hmpps-npm-script-allowlist | AI (phantom-deps): Same-org tooling invoked via scripts, not directly imported in source. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 6.0.0 | 5 / 28 | |
| 5.5.0 | 5 / 28 | |
| 5.4.1 | 5 / 28 | |
| 5.4.0 | 5 / 28 | |
| 5.3.6 | 5 / 28 | |
| 5.3.5 | 5 / 28 | |
| 5.3.4 | 5 / 28 | |
| 5.3.3 | 5 / 28 | |
| 5.3.2 | 5 / 28 | |
| 5.3.1 | 5 / 28 | |
| 5.3.0 | 5 / 28 | |
| 5.2.3 | 6 / 27 | |
| 5.2.2 | 6 / 27 | |
| 5.2.0 | 5 / 26 | |
| 5.1.1 | 5 / 26 | |
| 5.1.0 | 5 / 26 | |
| 5.0.1 | 5 / 26 | |
| 5.0.0 | 5 / 29 |
v6.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.