← Home

@omnia/fx

24
Versions
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

diego-souza-omniamickejohannessonandtii

Keywords

omniaomniafxextensionoffice365sharepoint

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Large enterprise framework; short README and no-op entry point are expected for a sub-package/type-only bundle. ai
phantom-deps phantom-dep:prosemirror-collab AI (phantom-deps): ProseMirror peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:prosemirror-commands AI (phantom-deps): ProseMirror peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:prosemirror-transform AI (phantom-deps): ProseMirror peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:prosemirror-dropcursor AI (phantom-deps): ProseMirror peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:prosemirror-inputrules AI (phantom-deps): ProseMirror peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:vue-property-decorator AI (phantom-deps): Vue peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:prosemirror-schema-list AI (phantom-deps): ProseMirror peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:orderedmap AI (phantom-deps): ProseMirror/tiptap peer dep pattern; stable false positive for this package. ai
phantom-deps phantom-dep:splitpanes AI (phantom-deps): UI component peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:broadcast-channel AI (phantom-deps): Peer dep pattern; stable false positive for this package. ai
phantom-deps phantom-dep:prosemirror-utils AI (phantom-deps): ProseMirror peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:@microsoft/signalr AI (phantom-deps): Peer dep pattern; stable false positive for this package. ai
phantom-deps phantom-dep:prosemirror-keymap AI (phantom-deps): ProseMirror peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:prosemirror-history AI (phantom-deps): ProseMirror peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:vue-class-component AI (phantom-deps): Vue peer dep; stable false positive for this package. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Same rationale as pg; scoped name @omnia/fx is not a typosquat of 'qs'. ai
phantom-deps phantom-dep:mousetrap AI (phantom-deps): Large framework; phantom-dep heuristic fires on config-referenced deps, stable false positive. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): TypeScript declared as dep for type support; stable false positive for this SDK. ai
phantom-deps phantom-dep:tiptap-extensions AI (phantom-deps): Rich-text editor deps referenced in config; stable false positive for this framework. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped package @omnia/fx cannot plausibly typosquat single-letter 'pg'; Levenshtein distance on scoped names is misleading. ai
install-scripts install-script:postinstall AI (install-scripts): Established enterprise SDK; postinstall runs node postinstall.js for documented setup, consistent across 6468 versions. ai

Versions (showing 24 of 24)

Version Deps Published
7.11.8 30 / 0
7.11.4 30 / 0
7.11.2 30 / 0
7.9.42 30 / 0
7.9.41 30 / 0
7.9.26 30 / 0
7.9.25 30 / 0
7.9.23 30 / 0
7.9.20 30 / 0
7.9.14 30 / 0
7.9.12 30 / 0
7.9.11 30 / 0
7.9.10 30 / 0
7.9.9 30 / 0
7.9.6 30 / 0
7.9.1 30 / 0
7.9.0 30 / 0
7.8.14 30 / 0
7.8.10 30 / 0
7.8.8 30 / 0
7.8.6 30 / 0
7.8.3 30 / 0
7.8.2 30 / 0
7.8.1 30 / 0

v7.11.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.11.4

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node postinstall.js

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.11.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.8.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.8.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.8.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.8.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.8.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.