@quintype/components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:redux | AI (phantom-deps): Peer/transitive usage via react-redux; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:papaparse | AI (phantom-deps): Optional/lazy-loaded dependency; stable pattern for this component library. | ai | |
| phantom-deps | phantom-dep:react-youtube | AI (phantom-deps): Optional/lazy-loaded video component; stable pattern. | ai | |
| phantom-deps | phantom-dep:react-dailymotion | AI (phantom-deps): Optional/lazy-loaded video component; stable pattern. | ai | |
| phantom-deps | phantom-dep:@brightcove/react-player-loader | AI (phantom-deps): Optional/lazy-loaded video component; stable pattern. | ai | |
| npm-metadata | url-dep:react-dfp | AI (npm-metadata): Points to quintype's own GitHub fork; consistent across versions. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 3.8.9 | 17 / 40 | |
| 3.8.8 | 17 / 40 | |
| 3.8.7 | 17 / 40 | |
| 3.8.6 | 17 / 40 | |
| 3.8.5 | 17 / 40 | |
| 3.8.4 | 17 / 40 | |
| 3.8.3 | 17 / 40 | |
| 3.8.2 | 17 / 40 | |
| 3.8.1 | 17 / 40 | |
| 3.8.0 | 17 / 40 | |
| 3.7.0 | 16 / 40 | |
| 3.6.3 | 16 / 40 | |
| 3.6.0 | 16 / 40 | |
| 3.5.2 | 16 / 40 | |
| 3.5.1 | 16 / 40 |
v3.8.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nandakishore) than the most recent previously approved version (reena07111996) on 2025-03-20, but nandakishore is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.8.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.8.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.8.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (reena07111996) than the most recent previously approved version (ags1773) on 2025-01-21, but reena07111996 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.8.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vishwanath.reddy) than the most recent previously approved version (ags1773) on 2024-12-17, but vishwanath.reddy is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.8.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ags1773) than the most recent previously approved version (vishwanath.reddy) on 2024-10-10, but ags1773 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.8.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ags1773) than the most recent previously approved version (vishwanath.reddy) on 2024-10-10, but ags1773 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.7.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vishwanath.reddy) than the most recent previously approved version (arunabhthakur94) on 2024-09-10, but vishwanath.reddy is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.6.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (arunabhthakur94) than the most recent previously approved version (reena07111996) on 2024-08-29, but arunabhthakur94 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.6.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (reena07111996) than the most recent previously approved version (vishwanath.reddy) on 2024-08-22, but reena07111996 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.5.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vishwanath.reddy) than the most recent previously approved version (ags1773) on 2024-07-24, but vishwanath.reddy is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.