@omnia/workplace
Omnia Workplace.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): Provenance confirms andtii is a known maintainer email match, not a hijack. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Long-standing type-definitions/meta package with 2053 versions; empty stub is expected. | ai |
Versions (showing 5 of 105)
| Version | Deps | Published |
|---|---|---|
| 7.5.22 | 0 / 0 | |
| 7.5.21 | 0 / 0 | |
| 7.5.20 | 0 / 0 | |
| 7.5.19 | 0 / 0 | |
| 7.5.18 | 0 / 0 |
v7.5.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.5.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.5.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.5.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.5.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.