@mseva/digit-ui-module-challangeneration
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Manual publish by known maintainer; no behavior change vs approved sibling. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Normal growth from bundling more UI components, no malicious payload found. | ai | |
| source-diff | net-exec-file:dist/index.modern.js | AI (source-diff): Bundle is a standard React/Redux UI module; no actual network fetch or dynamic code execution present in the sample. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Part of @mseva/digit-ui internal module ecosystem; sparse metadata is a pattern across the suite, not a spam indicator. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent with the rest of the @mseva/digit-ui module family; not a malice signal. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): React UI module; react-dom declared as dep but used transitively — stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-table | AI (phantom-deps): UI module with table components; phantom-dep heuristic fires on config references — stable false positive. | ai | |
| phantom-deps | phantom-dep:lodash.merge | AI (phantom-deps): Utility dep used in config/build context; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:redux-thunk | AI (phantom-deps): Redux-based UI module; redux-thunk used via config/middleware setup — stable false positive. | ai | |
| phantom-deps | phantom-dep:microbundle-crl | AI (phantom-deps): Build tool listed in scripts; phantom-dep heuristic fires on config reference — stable false positive. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 1.0.33 | 14 / 0 | |
| 1.0.32 | 14 / 0 | |
| 1.0.31 | 14 / 0 | |
| 1.0.30 | 14 / 0 | |
| 1.0.29 | 14 / 0 | |
| 1.0.28 | 14 / 0 | |
| 1.0.27 | 14 / 0 | |
| 1.0.26 | 14 / 0 | |
| 1.0.25 | 14 / 0 | |
| 1.0.24 | 14 / 0 | |
| 1.0.23 | 14 / 0 | |
| 1.0.22 | 14 / 0 | |
| 1.0.21 | 14 / 0 | |
| 1.0.20 | 14 / 0 | |
| 1.0.19 | 14 / 0 | |
| 1.0.18 | 14 / 0 | |
| 1.0.17 | 14 / 0 | |
| 1.0.16 | 14 / 0 | |
| 1.0.15 | 14 / 0 | |
| 1.0.14 | 14 / 0 | |
| 1.0.13 | 14 / 0 | |
| 1.0.12 | 13 / 0 | |
| 1.0.11 | 13 / 0 | |
| 1.0.10 | 13 / 0 | |
| 1.0.9 | 13 / 0 | |
| 1.0.8 | 13 / 0 | |
| 1.0.7 | 13 / 0 | |
| 1.0.6 | 13 / 0 | |
| 1.0.5 | 13 / 0 | |
| 1.0.4 | 13 / 0 | |
| 1.0.3 | 9 / 0 | |
| 1.0.2 | 9 / 0 | |
| 1.0.1 | 9 / 0 | |
| 1.0.0 | 9 / 0 |
v1.0.33
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (narinderkumar1) than the most recent previously approved version (anou1234) on 2026-05-12, but narinderkumar1 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.32
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (narinderkumar1) than the most recent previously approved version (anou1234) on 2026-05-07, but narinderkumar1 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.28
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: anujsingh32.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.27
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nayandhawan.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (anujsingh32) on 2025-12-31, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.25
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nayandhawan.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (anujsingh32) on 2025-11-28, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.24
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: anujsingh32.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.17
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anujsingh32) than the most recent previously approved version (nayandhawan) on 2025-11-17, but anujsingh32 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.10
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nayandhawan.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (anujsingh32) on 2025-11-06, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.