← Home

@openfin/workspace-platform

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

openfincolinhuopenfinbrandonpierrebaizenoyangundaymichaelmcoatesalan15008imansurijohnmandia-openfinrdepenatgoc99wenjuncheharsimran.openfin.singhmichal-pichlinski-hereluiemiliolicui3936connormccaffertyopenfin-cichrishobsonexperoliangliu-hererichbrowne-openfinazizyokhzhi0209openfin-gavinoblargnewaz.sharifandy.westacottshahossaineugeneross-openfingouthamcopenfin-jeffsakibahmadmanamiuedaxyopenfinhannahmcmillensmocarskidavidcoxon-of__tomasz__galim.kaudinovife-dev1gallak-openfineheyderelliott.burrmjoslingyoge-openfinhina-khalidcrom83eoyewobiyongji.chenmarek_openfinjmransegnolaameet-openfinrutu-bmichalzzopenfin-johansandrewche3openfin-ci-ghuday.guntupallipvidhiache40ahkjeffersongarcia25tpatek17cezary_openfinoliviatarsinicknewman-herericardo.martini-here.io

Keywords

clientapiworkspaceplatform

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Move to GitHub Actions CI publish within the @openfin org scope; benign transition. ai
maintainer-change maintainer-added AI (maintainer-change): Maintainer churn within established @openfin org; no malicious behavior present. ai
phantom-deps phantom-dep:aws-sdk AI (phantom-deps): Config-referenced, common for bundled workspace platform code. ai
phantom-deps phantom-dep:hi-base32 AI (phantom-deps): Config-referenced utility, false positive pattern. ai
phantom-deps phantom-dep:nprogress AI (phantom-deps): Config-referenced utility, false positive pattern. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Standard peer of react, bundler resolves indirectly. ai
phantom-deps phantom-dep:tinycolor2 AI (phantom-deps): Config-referenced utility, false positive pattern. ai
phantom-deps phantom-dep:react-color AI (phantom-deps): Config-referenced utility, false positive pattern. ai
phantom-deps phantom-dep:react-query AI (phantom-deps): Config-referenced utility, false positive pattern. ai
phantom-deps phantom-dep:react-redux AI (phantom-deps): Config-referenced utility, false positive pattern. ai
phantom-deps phantom-dep:lodash.merge AI (phantom-deps): Config-referenced utility, false positive pattern. ai
phantom-deps phantom-dep:@sentry/react AI (phantom-deps): Config-referenced monitoring lib, false positive pattern. ai
phantom-deps phantom-dep:framer-motion AI (phantom-deps): Config-referenced UI lib, false positive pattern. ai
phantom-deps phantom-dep:focus-trap-react AI (phantom-deps): Config-referenced UI lib, false positive pattern. ai
phantom-deps phantom-dep:copy-to-clipboard AI (phantom-deps): Config-referenced utility, false positive pattern. ai
phantom-deps phantom-dep:@openfin/microsoft365 AI (phantom-deps): Same-org OpenFin package, benign. ai
phantom-deps phantom-dep:openfin-notifications AI (phantom-deps): Same-org OpenFin package, benign. ai
phantom-deps phantom-dep:@radix-ui/react-dropdown-menu AI (phantom-deps): Config-referenced UI lib, false positive pattern. ai
phantom-deps phantom-dep:next AI (phantom-deps): Used via build config, not direct import; normal for Next-based bundle. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in minified SDK bundle; consistent with template/parser patterns in this established OpenFin workspace package. ai

Versions (showing 51 of 93)

View all versions
Version Deps Published
45.1.11 6 / 0
45.1.10 6 / 0
45.1.9 6 / 0
45.1.8 6 / 0
45.1.7 6 / 0
45.1.6 6 / 0
45.1.5 6 / 0
45.1.4 6 / 0
45.1.3 6 / 0
45.1.2 6 / 0
45.1.1 6 / 0
45.1.0 6 / 0
45.0.15 6 / 0
45.0.14 6 / 0
45.0.13 6 / 0
45.0.12 6 / 0
45.0.11 6 / 0
45.0.10 6 / 0
45.0.9 6 / 0
45.0.8 6 / 0
45.0.7 6 / 0
45.0.6 6 / 0
45.0.5 6 / 0
45.0.4 6 / 0
45.0.3 6 / 0
45.0.2 6 / 0
45.0.1 6 / 0
45.0.0 6 / 0
24.1.6 6 / 0
24.1.5 6 / 0
24.1.4 6 / 0
24.1.3 6 / 0
24.1.2 6 / 0
24.1.1 6 / 0
24.0.19 6 / 0
24.0.18 6 / 0
24.0.17 6 / 0
24.0.16 6 / 0
24.0.15 6 / 0
24.0.14 6 / 0
24.0.13 6 / 0
24.0.12 6 / 0
24.0.11 6 / 0
24.0.10 6 / 0
24.0.9 6 / 0
24.0.8 6 / 0
24.0.7 6 / 0
24.0.5 6 / 0
23.2.23 6 / 0
23.2.22 6 / 0
23.2.21 6 / 0

v45.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v45.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v24.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v24.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.