@open-formulieren/sdk
[](https://www.npmjs.com/package/@open-formulieren/sdk) [](https://codecov
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Config-file reference only; stable false positive for this SDK package. | ai | |
| phantom-deps | phantom-dep:@date-fns/tz | AI (phantom-deps): Config-file reference only; stable false positive for this SDK package. | ai | |
| phantom-deps | phantom-dep:tinyduration | AI (phantom-deps): Config-file reference only; stable false positive for this SDK package. | ai | |
| phantom-deps | phantom-dep:nuqs | AI (phantom-deps): Config-file reference only; stable false positive for this SDK package. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:flatpickr | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:ibantools | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:use-immer | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:leaflet-draw | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:proj4leaflet | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:react-formio | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:react-select | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:@sentry/react | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:react-leaflet | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:@floating-ui/react | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:@utrecht/table-css | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:react-leaflet-draw | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:zod-formik-adapter | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:react-number-format | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:immer | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:leaflet | AI (phantom-deps): SDK bundle pattern; deps declared for consumers, not directly imported in source. | ai |
v3.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.4.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.