@reltio/data-model
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@reltio/mdm-sdk | AI (dependencies): Same-org scoped dependency (@reltio); expected internal dependency pattern for this package family. | ai | |
| dependencies | unvetted-dep:@reltio/mdm-module | AI (dependencies): Same-org scoped dependency (@reltio); expected internal dependency pattern for this package family. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-sdk | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for bundled packages. | ai | |
| phantom-deps | phantom-dep:@reltio/components | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for bundled packages. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires in bundled output (bundle.js); standard webpack/rollup artifact for this UI component package. | ai | |
| phantom-deps | phantom-dep:graphology | AI (phantom-deps): Likely bundled into bundle.js output; phantom-dep heuristic unreliable for bundled packages. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-module | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for bundled packages. | ai | |
| bogus-package | bogus-package | AI (bogus-package): 507-version org-scoped package; missing metadata is a style issue, not a spam/malware indicator. | ai |
Versions (showing 52 of 155)
| Version | Deps | Published |
|---|---|---|
| 1.4.2249 | 4 / 0 | |
| 1.4.2248 | 4 / 0 | |
| 1.4.2247 | 4 / 0 | |
| 1.4.2246 | 4 / 0 | |
| 1.4.2245 | 4 / 0 | |
| 1.4.2244 | 4 / 0 | |
| 1.4.2243 | 4 / 0 | |
| 1.4.2242 | 4 / 0 | |
| 1.4.2241 | 4 / 0 | |
| 1.4.2240 | 4 / 0 | |
| 1.4.2239 | 4 / 0 | |
| 1.4.2238 | 4 / 0 | |
| 1.4.2237 | 4 / 0 | |
| 1.4.2236 | 4 / 0 | |
| 1.4.2235 | 4 / 0 | |
| 1.4.2234 | 4 / 0 | |
| 1.4.2233 | 4 / 0 | |
| 1.4.2232 | 4 / 0 | |
| 1.4.2231 | 4 / 0 | |
| 1.4.2230 | 4 / 0 | |
| 1.4.2229 | 4 / 0 | |
| 1.4.2228 | 4 / 0 | |
| 1.4.2227 | 4 / 0 | |
| 1.4.2226 | 4 / 0 | |
| 1.4.2225 | 4 / 0 | |
| 1.4.2224 | 4 / 0 | |
| 1.4.2223 | 4 / 0 | |
| 1.4.2222 | 4 / 0 | |
| 1.4.2221 | 4 / 0 | |
| 1.4.2220 | 4 / 0 | |
| 1.4.2219 | 4 / 0 | |
| 1.4.2218 | 4 / 0 | |
| 1.4.2217 | 4 / 0 | |
| 1.4.2216 | 4 / 0 | |
| 1.4.2215 | 4 / 0 | |
| 1.4.2214 | 4 / 0 | |
| 1.4.2213 | 4 / 0 | |
| 1.4.2212 | 4 / 0 | |
| 1.4.2211 | 4 / 0 | |
| 1.4.2210 | 4 / 0 | |
| 1.4.2209 | 4 / 0 | |
| 1.4.2208 | 4 / 0 | |
| 1.4.2207 | 4 / 0 | |
| 1.4.2206 | 4 / 0 | |
| 1.4.2205 | 4 / 0 | |
| 1.4.2204 | 4 / 0 | |
| 1.4.2203 | 4 / 0 | |
| 1.4.2202 | 4 / 0 | |
| 1.4.2201 | 4 / 0 | |
| 1.4.2200 | 4 / 0 | |
| 1.4.2199 | 4 / 0 | |
| 1.4.2198 | 4 / 0 |
v1.4.2249
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2248
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2247
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2246
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2245
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2244
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2243
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2242
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2241
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2240
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2239
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2238
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2237
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2236
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2235
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2234
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2233
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2232
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2231
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2230
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2229
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2228
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2227
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2226
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2225
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2224
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2223
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2222
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2221
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2220
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2219
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2218
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2217
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2216
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2215
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2214
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2213
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2212
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2211
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2210
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2209
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2208
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2207
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2206
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2205
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2204
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2203
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2202
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2201
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2200
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2199
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2198
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.