@openfin/remote-adapter
Establish intermachine runtime connections using webRTC.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): CI/CD-driven publish transition for established OpenFin package, not compromise indicator. | ai | |
| provenance | missing-githead | AI (provenance): Manual publish by known maintainer openfin-ci, consistent with prior versions. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): lodash is a well-known, vetted dependency; swap from es-toolkit is benign refactor. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI/CD publishing pipeline; rapid successive publishes are expected for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established OpenFin org package; lack of provenance is consistent across all 620 versions. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit runtime dep for TypeScript-compiled bundles; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:openfin-adapter | AI (phantom-deps): Bundled via bundleDependencies; not directly imported as a module but legitimately included. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() used inside a Proxy trap handler — standard JS pattern, not obfuscation. | ai | |
| npm-metadata | url-dep:openfin-adapter | AI (npm-metadata): file: path is a monorepo internal dep bundled at publish; not a runtime registry bypass risk. | ai | |
| dependencies | unvetted-dep:openfin-adapter | AI (dependencies): file: dep is a monorepo bundling pattern; openfin-adapter is listed in bundleDependencies and bundled at publish time. | ai |
Versions (showing 51 of 87)
| Version | Deps | Published |
|---|---|---|
| 46.100.44 | 3 / 0 | |
| 46.100.43 | 3 / 0 | |
| 46.100.42 | 3 / 0 | |
| 46.100.40 | 3 / 0 | |
| 46.100.39 | 3 / 0 | |
| 46.100.38 | 3 / 0 | |
| 46.100.37 | 3 / 0 | |
| 46.100.36 | 3 / 0 | |
| 46.100.35 | 3 / 0 | |
| 46.100.32 | 3 / 0 | |
| 46.100.31 | 3 / 0 | |
| 46.100.30 | 3 / 0 | |
| 46.100.29 | 3 / 0 | |
| 46.100.28 | 3 / 0 | |
| 46.100.27 | 3 / 0 | |
| 46.100.26 | 3 / 0 | |
| 46.100.25 | 3 / 0 | |
| 46.100.24 | 3 / 0 | |
| 46.100.23 | 3 / 0 | |
| 46.100.22 | 3 / 0 | |
| 46.100.21 | 3 / 0 | |
| 46.100.20 | 3 / 0 | |
| 46.100.17 | 3 / 0 | |
| 46.100.16 | 3 / 0 | |
| 46.100.10 | 3 / 0 | |
| 46.100.9 | 3 / 0 | |
| 46.100.8 | 3 / 0 | |
| 46.100.7 | 3 / 0 | |
| 46.100.6 | 3 / 0 | |
| 46.100.5 | 3 / 0 | |
| 46.100.4 | 3 / 0 | |
| 46.100.3 | 3 / 0 | |
| 46.100.2 | 3 / 0 | |
| 46.100.1 | 3 / 0 | |
| 45.100.107 | 3 / 0 | |
| 45.100.106 | 3 / 0 | |
| 45.100.105 | 3 / 0 | |
| 45.100.104 | 3 / 0 | |
| 45.100.103 | 3 / 0 | |
| 45.100.102 | 3 / 0 | |
| 45.100.101 | 3 / 0 | |
| 45.100.100 | 3 / 0 | |
| 45.100.99 | 3 / 0 | |
| 45.100.98 | 3 / 0 | |
| 45.100.95 | 3 / 0 | |
| 45.100.94 | 3 / 0 | |
| 45.100.93 | 3 / 0 | |
| 45.100.92 | 3 / 0 | |
| 45.100.91 | 3 / 0 | |
| 45.100.90 | 3 / 0 | |
| 45.100.89 | 3 / 0 |
v46.100.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.32
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2026-07-09. This could indicate a legitimate maintainer transition or an account compromise.
v46.100.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v46.100.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.107
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.106
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.105
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.104
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.103
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.102
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.101
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v45.100.100
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.