@reltio/dq-dashboard
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@reltio/mdm-sdk | AI (phantom-deps): Same-org scoped dep in a bundled package; phantom-dep false positive stable across versions. | ai | |
| phantom-deps | phantom-dep:@reltio/dashboard | AI (phantom-deps): Same-org scoped dep in a bundled package; phantom-dep false positive stable across versions. | ai | |
| phantom-deps | phantom-dep:@reltio/components | AI (phantom-deps): Same-org scoped dep in a bundled package; phantom-dep false positive stable across versions. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-module | AI (phantom-deps): Same-org scoped dep in a bundled package; phantom-dep false positive stable across versions. | ai | |
| phantom-deps | phantom-dep:react-window | AI (phantom-deps): Referenced in config files; bundled output pattern means direct import not visible to analyzer. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal Reltio component library; missing public metadata is expected for org-internal packages. | ai |
Versions (showing 51 of 372)
| Version | Deps | Published |
|---|---|---|
| 1.4.2357 | 5 / 0 | |
| 1.4.2356 | 5 / 0 | |
| 1.4.2354 | 5 / 0 | |
| 1.4.2353 | 5 / 0 | |
| 1.4.2352 | 5 / 0 | |
| 1.4.2351 | 5 / 0 | |
| 1.4.2350 | 5 / 0 | |
| 1.4.2349 | 5 / 0 | |
| 1.4.2348 | 5 / 0 | |
| 1.4.2347 | 5 / 0 | |
| 1.4.2346 | 5 / 0 | |
| 1.4.2345 | 5 / 0 | |
| 1.4.2344 | 5 / 0 | |
| 1.4.2343 | 5 / 0 | |
| 1.4.2342 | 5 / 0 | |
| 1.4.2341 | 5 / 0 | |
| 1.4.2339 | 5 / 0 | |
| 1.4.2338 | 5 / 0 | |
| 1.4.2337 | 5 / 0 | |
| 1.4.2336 | 5 / 0 | |
| 1.4.2335 | 5 / 0 | |
| 1.4.2334 | 5 / 0 | |
| 1.4.2333 | 5 / 0 | |
| 1.4.2332 | 5 / 0 | |
| 1.4.2331 | 5 / 0 | |
| 1.4.2330 | 5 / 0 | |
| 1.4.2329 | 5 / 0 | |
| 1.4.2328 | 5 / 0 | |
| 1.4.2327 | 5 / 0 | |
| 1.4.2326 | 5 / 0 | |
| 1.4.2325 | 5 / 0 | |
| 1.4.2324 | 5 / 0 | |
| 1.4.2323 | 5 / 0 | |
| 1.4.2322 | 5 / 0 | |
| 1.4.2321 | 5 / 0 | |
| 1.4.2320 | 5 / 0 | |
| 1.4.2319 | 5 / 0 | |
| 1.4.2318 | 5 / 0 | |
| 1.4.2317 | 5 / 0 | |
| 1.4.2316 | 5 / 0 | |
| 1.4.2315 | 5 / 0 | |
| 1.4.2314 | 5 / 0 | |
| 1.4.2313 | 5 / 0 | |
| 1.4.2312 | 5 / 0 | |
| 1.4.2311 | 5 / 0 | |
| 1.4.2310 | 5 / 0 | |
| 1.4.2309 | 5 / 0 | |
| 1.4.2308 | 5 / 0 | |
| 1.4.2307 | 5 / 0 | |
| 1.4.2306 | 5 / 0 | |
| 1.4.2305 | 5 / 0 |
v1.4.2357
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2356
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2354
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2353
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2352
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2351
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2350
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2349
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2348
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2347
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2346
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.