@oracle/oraclejet-core-pack
JET core components fully implemented in VDOM
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:oj-c/min/progress-button.js | AI (source-diff): Minified AMD build output of official JET component, not obfuscation. | ai | |
| source-diff | obfuscated-file:oj-c/min/toolbar.js | AI (source-diff): Bundled/minified AMD build output from Oracle's official build, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are bundled webdriver docs/min JS, consistent with routine version bumps. | ai | |
| source-diff | obfuscated-file:oj-c/min/rich-radioset.js | AI (source-diff): AMD-minified UI component code, standard build output for this package. | ai | |
| source-diff | obfuscated-file:oj-c/min/rich-checkboxset.js | AI (source-diff): AMD-minified UI component code, standard build output for this package. | ai | |
| source-diff | obfuscated-file:oj-c/min/dialog.js | AI (source-diff): Minified AMD bundle output from Oracle's build, not obfuscation. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party Oracle JET packages at matching version. | ai | |
| provenance | publisher-changed | AI (provenance): wlouie-orcl is an established Oracle org publisher with 45 approved packages; internal maintainer rotation. | ai | |
| dependencies | unvetted-dep:@oracle/oraclejet | AI (dependencies): First-party Oracle dependency; expected and stable for this package family across all versions. | ai | |
| source-diff | obfuscated-file:webdriver/docs/assets/search.js | AI (source-diff): TypeDoc-generated base64-encoded search index; standard documentation asset for this Oracle package. | ai | |
| source-diff | obfuscated-file:webdriver/docs/assets/navigation.js | AI (source-diff): TypeDoc-generated base64-encoded navigation data; standard documentation asset for this Oracle package. | ai | |
| source-diff | obfuscated-file:webdriver/docs/assets/main.js | AI (source-diff): TypeDoc-generated lunr.js search bundle; standard minified documentation asset for this Oracle package. | ai | |
| license | uncommon-license:UPL-1.0 | AI (license): UPL-1.0 is Oracle's standard open-source license used consistently across all Oracle JET packages. | ai | |
| provenance | no-provenance | AI (provenance): Established Oracle package family; provenance absence is consistent across all versions and not a meaningful risk signal here. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 20.1.3 | 5 / 0 | |
| 20.1.2 | 5 / 0 | |
| 20.1.1 | 5 / 0 | |
| 20.1.0 | 5 / 0 | |
| 20.0.6 | 5 / 0 | |
| 20.0.5 | 5 / 0 | |
| 20.0.4 | 5 / 0 | |
| 20.0.3 | 5 / 0 | |
| 20.0.2 | 5 / 0 | |
| 20.0.1 | 5 / 0 | |
| 20.0.0 | 5 / 0 | |
| 18.1.10 | 3 / 0 | |
| 18.1.9 | 3 / 0 | |
| 18.1.8 | 3 / 0 | |
| 18.1.7 | 3 / 0 | |
| 18.1.6 | 3 / 0 | |
| 18.0.15 | 3 / 0 | |
| 18.0.14 | 3 / 0 | |
| 18.0.13 | 3 / 0 | |
| 18.0.12 | 3 / 0 | |
| 18.0.11 | 3 / 0 | |
| 18.0.10 | 3 / 0 | |
| 17.1.9 | 3 / 0 | |
| 17.1.8 | 3 / 0 | |
| 17.0.11 | 3 / 0 |
v20.1.3
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (meghana-vadlapally) than the most recent previously approved version (smadeghe-orcl) on 2026-07-15, but meghana-vadlapally is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v20.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (meghana-vadlapally) than the most recent previously approved version (wlouie-orcl) on 2026-04-03, but meghana-vadlapally is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v20.0.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wlouie-orcl) than the most recent previously approved version (smadeghe-orcl) on 2026-03-18, but wlouie-orcl is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v20.0.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wlouie-orcl) than the most recent previously approved version (smadeghe-orcl) on 2026-02-16, but wlouie-orcl is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.1.10
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.1.8
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (meghana-vadlapally) than the most recent previously approved version (wlouie-orcl) on 2026-03-18, but meghana-vadlapally is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.1.7
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.1.6
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wlouie-orcl) than the most recent previously approved version (smadeghe-orcl) on 2026-01-23, but wlouie-orcl is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.0.15
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (smadeghe-orcl) than the most recent previously approved version (meghana-vadlapally) on 2026-07-09, but smadeghe-orcl is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.0.13
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (meghana-vadlapally) than the most recent previously approved version (wlouie-orcl) on 2026-03-18, but meghana-vadlapally is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.0.12
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v18.0.11
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wlouie-orcl) than the most recent previously approved version (smadeghe-orcl) on 2026-01-23, but wlouie-orcl is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v18.0.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v17.1.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.1.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v17.0.11
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wlouie-orcl) than the most recent previously approved version (smadeghe-orcl) on 2026-02-25, but wlouie-orcl is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.