@reltio/data-model
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@reltio/mdm-sdk | AI (dependencies): Same-org scoped dependency (@reltio); expected internal dependency pattern for this package family. | ai | |
| dependencies | unvetted-dep:@reltio/mdm-module | AI (dependencies): Same-org scoped dependency (@reltio); expected internal dependency pattern for this package family. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-sdk | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for bundled packages. | ai | |
| phantom-deps | phantom-dep:@reltio/components | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for bundled packages. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires in bundled output (bundle.js); standard webpack/rollup artifact for this UI component package. | ai | |
| phantom-deps | phantom-dep:graphology | AI (phantom-deps): Likely bundled into bundle.js output; phantom-dep heuristic unreliable for bundled packages. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-module | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for bundled packages. | ai | |
| bogus-package | bogus-package | AI (bogus-package): 507-version org-scoped package; missing metadata is a style issue, not a spam/malware indicator. | ai |
Versions (showing 51 of 152)
| Version | Deps | Published |
|---|---|---|
| 1.4.2352 | 4 / 0 | |
| 1.4.2351 | 4 / 0 | |
| 1.4.2350 | 4 / 0 | |
| 1.4.2349 | 4 / 0 | |
| 1.4.2348 | 4 / 0 | |
| 1.4.2347 | 4 / 0 | |
| 1.4.2346 | 4 / 0 | |
| 1.4.2345 | 4 / 0 | |
| 1.4.2344 | 4 / 0 | |
| 1.4.2343 | 4 / 0 | |
| 1.4.2342 | 4 / 0 | |
| 1.4.2341 | 4 / 0 | |
| 1.4.2340 | 4 / 0 | |
| 1.4.2339 | 4 / 0 | |
| 1.4.2338 | 4 / 0 | |
| 1.4.2337 | 4 / 0 | |
| 1.4.2336 | 4 / 0 | |
| 1.4.2335 | 4 / 0 | |
| 1.4.2334 | 4 / 0 | |
| 1.4.2333 | 4 / 0 | |
| 1.4.2332 | 4 / 0 | |
| 1.4.2331 | 4 / 0 | |
| 1.4.2330 | 4 / 0 | |
| 1.4.2329 | 4 / 0 | |
| 1.4.2328 | 4 / 0 | |
| 1.4.2327 | 4 / 0 | |
| 1.4.2326 | 4 / 0 | |
| 1.4.2325 | 4 / 0 | |
| 1.4.2324 | 4 / 0 | |
| 1.4.2323 | 4 / 0 | |
| 1.4.2322 | 4 / 0 | |
| 1.4.2321 | 4 / 0 | |
| 1.4.2320 | 4 / 0 | |
| 1.4.2319 | 4 / 0 | |
| 1.4.2318 | 4 / 0 | |
| 1.4.2317 | 4 / 0 | |
| 1.4.2316 | 4 / 0 | |
| 1.4.2315 | 4 / 0 | |
| 1.4.2314 | 4 / 0 | |
| 1.4.2313 | 4 / 0 | |
| 1.4.2312 | 4 / 0 | |
| 1.4.2311 | 4 / 0 | |
| 1.4.2310 | 4 / 0 | |
| 1.4.2309 | 4 / 0 | |
| 1.4.2308 | 4 / 0 | |
| 1.4.2304 | 4 / 0 | |
| 1.4.2303 | 4 / 0 | |
| 1.4.2302 | 4 / 0 | |
| 1.4.2301 | 4 / 0 | |
| 1.4.2300 | 4 / 0 | |
| 1.4.2299 | 4 / 0 |
v1.4.2352
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2351
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2350
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2349
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2348
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2347
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2346
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2345
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2344
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2343
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2342
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2341
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2340
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2339
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (egorshkov) than the most recent previously approved version (reltio-ui-coe) on 2026-04-28, but egorshkov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.2338
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (egorshkov) than the most recent previously approved version (reltio-ui-coe) on 2026-04-23, but egorshkov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.2337
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (egorshkov) than the most recent previously approved version (reltio-ui-coe) on 2026-04-23, but egorshkov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.2336
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2335
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2334
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2333
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2332
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2331
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2330
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2329
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2328
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2327
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2326
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2325
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2324
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2323
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2322
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2321
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2320
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2319
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2318
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2317
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2316
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2315
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2314
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (reltio-ui-coe) than the most recent previously approved version (vitaly.gerasev) on 2026-02-06, but reltio-ui-coe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.2313
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (reltio-ui-coe) than the most recent previously approved version (vitaly.gerasev) on 2026-01-27, but reltio-ui-coe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.2312
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (reltio-ui-coe) than the most recent previously approved version (vitaly.gerasev) on 2026-01-27, but reltio-ui-coe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.2311
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (reltio-ui-coe) than the most recent previously approved version (vitaly.gerasev) on 2026-01-27, but reltio-ui-coe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.2310
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (reltio-ui-coe) than the most recent previously approved version (vitaly.gerasev) on 2026-01-27, but reltio-ui-coe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.2309
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (reltio-ui-coe) than the most recent previously approved version (vitaly.gerasev) on 2026-01-23, but reltio-ui-coe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.2308
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (reltio-ui-coe) than the most recent previously approved version (vitaly.gerasev) on 2026-01-23, but reltio-ui-coe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.2304
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2303
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2302
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2301
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2300
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2299
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.