← Home

@openmrs/esm-bed-management-app

Bed management app for OpenMRS 3

5
Versions
MPL-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

mogoodrichopenmrs-botrkorytkowskidjazayerimksdbrandonesjdickbmamlindkibetdennisforthewinibacher

Keywords

openmrs

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/1480.js AI (source-diff): Standard webpack chunk containing i18n JSON; minification is expected for this build pipeline. ai
source-diff obfuscated-file:dist/1646.js AI (source-diff): Standard webpack chunk with i18n strings; expected minified output. ai
source-diff obfuscated-file:dist/1744.js AI (source-diff): Webpack chunk containing React/SWR library code; expected minified output. ai
source-diff obfuscated-file:dist/1789.js AI (source-diff): Webpack chunk with react-i18next and HTML parser; expected minified output. ai
source-diff obfuscated-file:dist/1869.js AI (source-diff): i18n JSON chunk; expected minified output. ai
source-diff obfuscated-file:dist/1877.js AI (source-diff): i18n JSON chunk (Portuguese); expected minified output. ai
source-diff obfuscated-file:dist/1893.js AI (source-diff): Webpack chunk with React form components; expected minified output. ai
source-diff obfuscated-file:dist/2257.js AI (source-diff): Webpack chunk with CSS modules and UI components; expected minified output. ai
source-diff net-exec-file:dist/2257.js AI (source-diff): Network calls are SWR data fetching; dynamic execution is React rendering — standard app pattern, not a dropper. ai
source-diff large-new-source-files AI (source-diff): Major version bump (10→11) with webpack rechunking produces many new chunk files; expected for this package. ai

Versions (showing 5 of 5)

Version Deps Published
11.1.0 6 / 2
11.0.1 6 / 2
11.0.0 6 / 2
10.0.2 6 / 1
10.0.0 6 / 1

v11.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.