@mseva/digit-ui-module-obps
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index.modern.js | AI (source-diff): Standard bundled React UI module; long lines are from bundler output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index.modern.js | AI (source-diff): Network calls and dynamic patterns are from legitimate React/Redux/react-query usage in a UI module bundle. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by addition of source maps (~16MB) and modern bundle format output. | ai | |
| phantom-deps | phantom-dep:jspdf | AI (phantom-deps): jspdf is a declared runtime dep used in build output; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:redux-thunk | AI (phantom-deps): redux-thunk is a declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:microbundle-crl | AI (phantom-deps): microbundle-crl is the build tool declared in scripts; not imported in source by design. | ai |
Versions (showing 40 of 140)
| Version | Deps | Published |
|---|---|---|
| 1.0.95 | 14 / 0 | |
| 1.0.94 | 14 / 0 | |
| 1.0.93 | 14 / 0 | |
| 1.0.92 | 14 / 0 | |
| 1.0.91 | 14 / 0 | |
| 1.0.90 | 14 / 0 | |
| 1.0.89 | 14 / 0 | |
| 1.0.88 | 14 / 0 | |
| 1.0.87 | 14 / 0 | |
| 1.0.86 | 14 / 0 | |
| 1.0.85 | 14 / 0 | |
| 1.0.84 | 14 / 0 | |
| 1.0.83 | 14 / 0 | |
| 1.0.82 | 14 / 0 | |
| 1.0.81 | 14 / 0 | |
| 1.0.80 | 14 / 0 | |
| 1.0.79 | 14 / 0 | |
| 1.0.78 | 14 / 0 | |
| 1.0.77 | 14 / 0 | |
| 1.0.76 | 14 / 0 | |
| 1.0.75 | 14 / 0 | |
| 1.0.74 | 14 / 0 | |
| 1.0.73 | 14 / 0 | |
| 1.0.72 | 14 / 0 | |
| 1.0.71 | 14 / 0 | |
| 1.0.70 | 14 / 0 | |
| 1.0.69 | 14 / 0 | |
| 1.0.68 | 14 / 0 | |
| 1.0.67 | 14 / 0 | |
| 1.0.41 | 14 / 0 | |
| 1.0.26 | 14 / 0 | |
| 1.0.14 | 11 / 0 | |
| 1.0.9 | 11 / 0 | |
| 1.0.8 | 11 / 0 | |
| 1.0.7 | 11 / 0 | |
| 1.0.6 | 11 / 0 | |
| 1.0.3 | 11 / 0 | |
| 1.0.2 | 11 / 0 | |
| 1.0.1 | 11 / 0 | |
| 1.0.0 | 11 / 0 |
v1.0.95
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.94
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.92
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.91
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.88
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.85
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.84
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-11-14, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.81
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-11-14, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.77
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.75
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (anujsingh32) on 2025-11-10, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.73
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.72
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-11-06, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.70
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-11-06, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.69
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-11-06, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.67
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (anujsingh32) on 2025-10-30, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.