← Home

@ministryofjustice/hmpps-forge

HMPPS Forge

4
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jamesboobierachimber-mojjohan-d-mojjbrightonmojmoj-igorpaulmasseyandrewrleepaulusp_mojmoj-ryantkxoen-mojmpbostock-mojcarloveo-mojmarcsteeven.ekmarcusaspinthomas-geraghty

Keywords

hmppsforgegovuknunjucksforms

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/plugin/panel.js AI (source-diff): Bundled preact devtools panel UI, not a loader; matches documented devtools export. ai
publish-pattern new-deps-added AI (publish-pattern): ws is a well-known package needed for the new devtools panel feature. ai

Versions (showing 4 of 4)

Version Deps Published
0.3.2 5 / 33
0.3.1 5 / 33
0.3.0 4 / 28
0.2.0 4 / 28

v0.3.2

2 findings
HIGH New file with network + code execution: dist/plugin/panel.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.1

2 findings
HIGH New file with network + code execution: dist/plugin/panel.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.