@ministryofjustice/hmpps-digital-prison-reporting-frontend
The Digital Prison Reporting Frontend contains templates and code to help display data effectively in UI applications.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@flipt-io/flipt-client-js | AI (phantom-deps): Used via dynamic/conditional import patterns; stable false positive. | ai | |
| source-diff | encoded-string-file:cjs/node_modules/@flipt-io/flipt-client-js/dist/node/index.js | AI (source-diff): Base64 string is the WASM binary for flipt-client-js feature-flag engine; expected and benign for this dependency. | ai | |
| phantom-deps | phantom-dep:cookie-parser | AI (phantom-deps): Referenced in test-app config; not directly imported by library. | ai | |
| phantom-deps | phantom-dep:chartjs-adapter-dayjs-3 | AI (phantom-deps): Charting adapter referenced in config/templates; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:connect-flash | AI (phantom-deps): Peer/consumer middleware; not directly imported by this library. | ai | |
| phantom-deps | phantom-dep:connect-redis | AI (phantom-deps): Peer/consumer middleware; not directly imported by this library. | ai | |
| phantom-deps | phantom-dep:govuk-frontend | AI (phantom-deps): Peer dependency for GOV.UK design system; consumers import directly. | ai | |
| phantom-deps | phantom-dep:nocache | AI (phantom-deps): Peer/consumer dependency pattern for this frontend library; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:@tsconfig/node24 | AI (phantom-deps): TypeScript config package; referenced in tsconfig, not imported in code. | ai | |
| phantom-deps | phantom-dep:@ministryofjustice/frontend | AI (phantom-deps): Same-org peer dependency; referenced in templates/config, not directly imported. | ai | |
| phantom-deps | phantom-dep:express-session | AI (phantom-deps): Peer/consumer middleware; not directly imported by this library. | ai | |
| phantom-deps | phantom-dep:chart.js | AI (phantom-deps): Peer dependency for charting; consumers import directly. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): Dev/build tooling dependency; not directly imported in library code. | ai | |
| phantom-deps | phantom-dep:concurrently | AI (phantom-deps): Dev tooling; not directly imported in library code. | ai |
Versions (showing 51 of 68)
| Version | Deps | Published |
|---|---|---|
| 6.7.0 | 24 / 0 | |
| 6.6.5 | 24 / 0 | |
| 6.6.4 | 25 / 0 | |
| 6.6.3 | 25 / 0 | |
| 6.6.2 | 25 / 0 | |
| 6.6.1 | 26 / 0 | |
| 6.6.0 | 26 / 0 | |
| 6.5.0 | 26 / 0 | |
| 6.4.1 | 26 / 0 | |
| 6.4.0 | 26 / 0 | |
| 6.3.3 | 26 / 0 | |
| 6.3.2 | 26 / 0 | |
| 6.3.1 | 26 / 0 | |
| 6.3.0 | 26 / 0 | |
| 6.2.4 | 26 / 0 | |
| 6.2.3 | 26 / 0 | |
| 6.2.2 | 26 / 0 | |
| 6.2.1 | 26 / 0 | |
| 6.2.0 | 26 / 0 | |
| 6.1.3 | 26 / 0 | |
| 6.1.2 | 26 / 0 | |
| 6.1.1 | 26 / 0 | |
| 6.1.0 | 26 / 0 | |
| 6.0.3 | 26 / 0 | |
| 6.0.2 | 26 / 0 | |
| 6.0.1 | 26 / 0 | |
| 6.0.0 | 26 / 0 | |
| 5.11.2 | 26 / 0 | |
| 5.11.0 | 26 / 0 | |
| 5.10.13 | 26 / 0 | |
| 5.10.11 | 26 / 0 | |
| 5.10.10 | 26 / 0 | |
| 5.10.9 | 26 / 0 | |
| 5.10.8 | 26 / 0 | |
| 5.10.7 | 26 / 0 | |
| 5.10.6 | 26 / 0 | |
| 5.10.5 | 26 / 0 | |
| 5.10.4 | 26 / 0 | |
| 5.10.3 | 26 / 0 | |
| 5.10.2 | 26 / 0 | |
| 5.10.1 | 26 / 0 | |
| 5.10.0 | 26 / 0 | |
| 5.9.0 | 26 / 0 | |
| 5.8.7 | 26 / 0 | |
| 5.8.6 | 26 / 0 | |
| 4.29.2 | 29 / 69 | |
| 4.29.0 | 29 / 69 | |
| 4.28.8 | 29 / 69 | |
| 4.28.5 | 29 / 69 | |
| 4.28.3 | 30 / 69 | |
| 4.28.2 | 30 / 69 |
v6.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.2
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.3.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.2.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.11.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.29.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.29.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.28.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.28.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.28.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.28.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.