@openfin/fdc3-api
OpenFin fdc3 module utilities and types.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Shift to GitHub Actions CI publisher, no behavioral change; benign automation transition. | ai | |
| provenance | missing-githead | AI (provenance): Manual publish by known maintainer openfin-ci, consistent with prior track record. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): lodash is a well-known, benign dependency swap for es-toolkit. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a declared runtime dependency; phantom-dep is a false positive here. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI/CD publishing pipeline; rapid successive publishes are expected for this package. | ai | |
| dependencies | unvetted-dep:openfin-adapter | AI (dependencies): openfin-adapter is a bundled dependency (bundleDependencies) from OpenFin's own monorepo; file: path is irrelevant at install time. | ai | |
| phantom-deps | phantom-dep:openfin-adapter | AI (phantom-deps): Bundled dependency; not directly imported as a module import is expected for this pattern. | ai | |
| npm-metadata | url-dep:openfin-adapter | AI (npm-metadata): Listed in bundleDependencies; the file: path is bundled at publish time, not resolved from the registry by consumers. | ai |
Versions (showing 51 of 157)
| Version | Deps | Published |
|---|---|---|
| 46.100.45 | 2 / 0 | |
| 46.100.44 | 2 / 0 | |
| 46.100.43 | 2 / 0 | |
| 46.100.42 | 2 / 0 | |
| 46.100.40 | 2 / 0 | |
| 46.100.39 | 2 / 0 | |
| 46.100.38 | 2 / 0 | |
| 46.100.37 | 2 / 0 | |
| 46.100.36 | 2 / 0 | |
| 46.100.35 | 2 / 0 | |
| 46.100.32 | 2 / 0 | |
| 46.100.31 | 2 / 0 | |
| 46.100.30 | 2 / 0 | |
| 46.100.29 | 2 / 0 | |
| 46.100.28 | 2 / 0 | |
| 46.100.27 | 2 / 0 | |
| 46.100.26 | 2 / 0 | |
| 46.100.25 | 2 / 0 | |
| 46.100.24 | 2 / 0 | |
| 46.100.23 | 2 / 0 | |
| 46.100.22 | 2 / 0 | |
| 46.100.21 | 2 / 0 | |
| 46.100.20 | 2 / 0 | |
| 46.100.19 | 2 / 0 | |
| 46.100.18 | 2 / 0 | |
| 46.100.17 | 2 / 0 | |
| 46.100.16 | 2 / 0 | |
| 46.100.10 | 2 / 0 | |
| 46.100.9 | 2 / 0 | |
| 46.100.8 | 2 / 0 | |
| 46.100.7 | 2 / 0 | |
| 46.100.6 | 2 / 0 | |
| 46.100.5 | 2 / 0 | |
| 46.100.4 | 2 / 0 | |
| 46.100.3 | 2 / 0 | |
| 46.100.2 | 2 / 0 | |
| 46.100.1 | 2 / 0 | |
| 45.100.107 | 2 / 0 | |
| 45.100.106 | 2 / 0 | |
| 45.100.105 | 2 / 0 | |
| 45.100.104 | 2 / 0 | |
| 45.100.103 | 2 / 0 | |
| 45.100.102 | 2 / 0 | |
| 45.100.101 | 2 / 0 | |
| 45.100.100 | 2 / 0 | |
| 45.100.99 | 2 / 0 | |
| 45.100.98 | 2 / 0 | |
| 45.100.95 | 2 / 0 | |
| 45.100.94 | 2 / 0 | |
| 45.100.93 | 2 / 0 | |
| 45.100.92 | 2 / 0 |
v46.100.45
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.44
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.107
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.106
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.105
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.104
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.103
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.102
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.101
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.100
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.