@openmrs/esm-patient-attachments-app
Patient attachments microfrontend for the OpenMRS SPA
9
Versions
MPL-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
mogoodrichopenmrs-botrkorytkowskidjazayerimksdbrandonesjdickbmamlindkibetdennisforthewinibacher
Keywords
openmrs
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Large number of new dist files is expected for a webpack-bundled microfrontend with dependency updates. | ai | |
| source-diff | obfuscated-file:dist/6519.js | AI (source-diff): Standard webpack minified bundle output for this OpenMRS microfrontend. | ai | |
| source-diff | obfuscated-file:dist/7247.js | AI (source-diff): Standard webpack minified bundle output for this OpenMRS microfrontend. | ai | |
| source-diff | obfuscated-file:dist/7646.js | AI (source-diff): Standard webpack minified bundle output for this OpenMRS microfrontend. | ai | |
| source-diff | obfuscated-file:dist/1789.js | AI (source-diff): Standard webpack minified bundle output for this OpenMRS microfrontend; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/2544.js | AI (source-diff): Standard webpack minified bundle output for this OpenMRS microfrontend; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/2544.js | AI (source-diff): Network calls and dynamic requires are normal in a webpack bundle for a React SPA; no malware indicators. | ai | |
| source-diff | obfuscated-file:dist/356.js | AI (source-diff): Standard webpack minified bundle output; CSS-in-JS and camera library code. | ai | |
| source-diff | net-exec-file:dist/356.js | AI (source-diff): Network calls and dynamic requires are normal in a webpack bundle for a React SPA; no malware indicators. | ai | |
| source-diff | obfuscated-file:dist/3739.js | AI (source-diff): Standard webpack minified bundle output for this OpenMRS microfrontend. | ai | |
| source-diff | obfuscated-file:dist/3989.js | AI (source-diff): Standard webpack minified bundle output; SWR library code clearly visible. | ai | |
| source-diff | obfuscated-file:dist/466.js | AI (source-diff): Standard webpack minified bundle output; React library code clearly visible. | ai | |
| source-diff | obfuscated-file:dist/4952.js | AI (source-diff): Standard webpack minified bundle output for this OpenMRS microfrontend. | ai | |
| source-diff | obfuscated-file:dist/5688.js | AI (source-diff): Standard webpack minified bundle output for this OpenMRS microfrontend. | ai | |
| source-diff | obfuscated-file:dist/5697.js | AI (source-diff): Standard webpack minified bundle output for this OpenMRS microfrontend. | ai | |
| source-diff | obfuscated-file:dist/6449.js | AI (source-diff): Standard webpack minified bundle output for this OpenMRS microfrontend. | ai | |
| source-diff | obfuscated-file:dist/6508.js | AI (source-diff): Standard webpack minified bundle output for this OpenMRS microfrontend. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): lodash-es commonly used via build tooling/config in OpenMRS monorepo; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-grid-gallery | AI (phantom-deps): react-grid-gallery is a declared runtime dep; phantom-dep heuristic misfires here. | ai | |
| phantom-deps | phantom-dep:linkifyjs | AI (phantom-deps): linkifyjs is a peer of linkify-react; referenced in config but used transitively — stable false positive for this package. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 12.3.4 | 7 / 3 | |
| 12.3.3 | 7 / 3 | |
| 12.3.2 | 7 / 3 | |
| 12.3.1 | 7 / 3 | |
| 12.3.0 | 7 / 3 | |
| 12.2.1 | 7 / 3 | |
| 12.2.0 | 7 / 3 | |
| 12.1.0 | 7 / 2 | |
| 12.0.0 | 7 / 2 |
v12.0.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.