← Home

@nice-devone/voice-sdk

NICE CXone Voice SDK

2
Versions
UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

seankirkbynice-devone-adminzach-colematejsimek

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@grafana/faro-web-sdk AI (phantom-deps): Same config-reference pattern as other accepted phantom deps in this package; consistent with observability tooling pattern. ai
phantom-deps phantom-dep:@grafana/faro-web-tracing AI (phantom-deps): Same config-reference pattern as other accepted phantom deps in this package; consistent with observability tooling pattern. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:react AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:lexical AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:cockatiel AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:linkifyjs AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:react-toastify AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:@reduxjs/toolkit AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:idb AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output, not direct imports. ai
phantom-deps phantom-dep:broadcast-channel AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:@microsoft/signalr AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:@datadog/browser-rum AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:@datadog/browser-logs AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:@testrtc/watchrtc-sdk AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai
phantom-deps phantom-dep:@nice-devone/shared-apps-lib AI (phantom-deps): Same org scope; consumed indirectly in bundled SDK. ai
phantom-deps phantom-dep:@nice-devone/i18n AI (phantom-deps): Same org scope; consumed indirectly in bundled SDK. ai
phantom-deps phantom-dep:util AI (phantom-deps): Bundled SDK; deps consumed indirectly via build output. ai

Versions (showing 2 of 2)

Version Deps Published
26.2.1 22 / 0
25.4.1 20 / 0

v26.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.