← Home

@procore/unified-viewer-flavors

1
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

alice.yujames.wiltonladavargadstarrprocore_halzygarett.bynum.procoreenyagagerardolopezduenas-procorewillpankoniensateesh-kadiyala-procorechris.berbertxin1safi.abdulepalinprocoremehrdad-panahandehtyler.wasden.procorejeremy.lunddineshkumar.jayakroniedias-procoreryanfuentesprocorestajicsbrocktillotsonprocorekyle.williamsgreg.spiesdtorres-procorenoor.aliari-procorealanprocorejl4everjames.lawsonajaykumar-procoredennis.heckmantara.chamberslalovar-procorejames.clearychadryderdevin.cunningham.procoreabhijit.patwardhanmaxscott_pclydiaharasherylnapigkitchangprocoreapcarroll_procoreandy.mayerbob.laskowskivinaya-procorer-pullingkahliholmesamanzhula-zoolatechandrew.wheelerleandro-procyadhu.prakashjason-kayeinitbar-procorejesse.olsenjsoncummingspatrick.lardinbrad.uraniian.nguyenallenanle.procoreismail.hassanbrookyboy009uddhavjoglekardancingshelljustinmwattsrysmithprocorebostonaholicrobbiegprocorejadamsssjeremy.bouzigarddallashall-procorebates550timdohertyb.bookoutjalyngchrisarevirhtaelespitruthysystemsdev-account-adminsseanwangbhargavrndfarismmkdannyporrellomcclaytongregburgerdanny.oumessanjaheyvettesoujgee67chriszhangarthurzhukcagmzmariah_delaneylukenispelkimhin267hyogmanjuliana.hernandezevan.freymillermanuphatakjudy-lu-pcprocore-it-supportwilfredrandrewburke-pcjkleintechrachel.arkebaueraaronmeprocore-npm-botlincolnpjames.dabbs-procorelaurenbrandsteinprocorekimtoddscottbieser-procorefkennedyzach.mckenzie.procorenatalie.waliakapoorlakshya-procoreshayonj_procoreheplayskeysmike.souththomasoboyledischordederek-carter-procoredlgassermoises.narvaez-procorecfprocorerory.forsterlgm_procoreevan.waitstodd-andrew-procorejeremy-marcusisrael-pereirajmejia-fslkedar.procoreersgonzalostephan-procorealeclarsenprocorehimansudesaiyihai.zweifeljay-rajanjacky-leibpross22peter.jin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@procore/core-icons AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for re-exported library packages. ai
phantom-deps phantom-dep:@procore/labs-i18n-extensions AI (phantom-deps): Same-org dep; stable false positive for this aggregation package. ai
phantom-deps phantom-dep:@procore/labs-custom-workflows AI (phantom-deps): Same-org dep; stable false positive for this aggregation package. ai
phantom-deps phantom-dep:@procore/labs-date-formatter AI (phantom-deps): Same-org dep; stable false positive for this aggregation package. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): Common utility; referenced in config files, stable false positive for this package. ai
phantom-deps phantom-dep:mime-types AI (phantom-deps): Also in devDependencies; phantom-dep heuristic misfires here. ai
phantom-deps phantom-dep:path-to-regexp AI (phantom-deps): Routing utility; stable false positive for this aggregation package. ai
provenance no-provenance AI (provenance): Procore org package; lack of Sigstore provenance is common and not a disqualifier here. ai

Versions (showing 1 of 1)

Version Deps Published
7.0.1 11 / 16