@mseva/digit-ui-module-engagement
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-tripled | AI (source-diff): Sourcemap + modern build files added, not injected payload. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Known publisher with strong approval track record; normal team rotation. | ai | |
| source-diff | obfuscated-file:dist/index.modern.js | AI (source-diff): File is a standard microbundle-crl output with readable named imports; long lines are minified bundle, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index.modern.js | AI (source-diff): Network calls and dynamic code are from React/Redux/react-query patterns in a UI module bundle, not dropper behavior. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal government/civic-tech UI module; sparse metadata is consistent with org-internal publishing practices across 44 versions. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a standard peer/build dep in React module packages; not directly imported in source is expected. | ai | |
| phantom-deps | phantom-dep:redux-thunk | AI (phantom-deps): redux-thunk used as runtime dep via redux middleware config, not directly imported in source files. | ai | |
| phantom-deps | phantom-dep:microbundle-crl | AI (phantom-deps): microbundle-crl is a build tool referenced in scripts, not imported in source; phantom-dep false positive. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 1.1.34 | 13 / 0 | |
| 1.1.33 | 13 / 0 | |
| 1.1.32 | 13 / 0 | |
| 1.1.31 | 13 / 0 | |
| 1.1.30 | 13 / 0 | |
| 1.1.28 | 13 / 0 | |
| 1.1.27 | 13 / 0 | |
| 1.1.25 | 13 / 0 | |
| 1.1.18 | 13 / 0 | |
| 1.1.17 | 13 / 0 | |
| 1.1.16 | 13 / 0 | |
| 1.1.15 | 13 / 0 | |
| 1.1.14 | 13 / 0 | |
| 1.1.7 | 13 / 0 | |
| 1.1.5 | 13 / 0 | |
| 1.1.2 | 13 / 0 | |
| 1.1.1 | 13 / 0 | |
| 1.1.0 | 13 / 0 | |
| 1.0.6 | 13 / 0 | |
| 1.0.5 | 13 / 0 | |
| 1.0.4 | 13 / 0 | |
| 1.0.3 | 13 / 0 | |
| 1.0.2 | 13 / 0 | |
| 1.0.1 | 13 / 0 | |
| 1.0.0 | 10 / 0 |
v1.1.30
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anujsingh32) than the most recent previously approved version (manasabadeti) on 2025-11-27, but anujsingh32 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.27
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anujsingh32) than the most recent previously approved version (manasabadeti) on 2025-08-21, but anujsingh32 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.25
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anujsingh32) than the most recent previously approved version (manasabadeti) on 2025-06-20, but anujsingh32 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.16
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anujsingh32) than the most recent previously approved version (manasabadeti) on 2025-05-16, but anujsingh32 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anujsingh32) than the most recent previously approved version (manasabadeti) on 2025-04-06, but anujsingh32 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.5
2 findingsThis version was published by a different npm account (manasabadeti) than the most recent previously approved version (anujsingh32) on 2025-04-04. It has since remained available on npm for 469 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anujsingh32) than the most recent previously approved version (deepakmori) on 2025-03-23, but anujsingh32 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.4
2 findingsThis version was published by a different npm account (deepakmori) than the most recent previously approved version (anujsingh32) on 2025-03-07. It has since remained available on npm for 497 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.