← Home

@reltio/graph

51
Versions
SEE LICENSE IN LICENSE FILE
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

egorshkovvitaly.gerasevalexander.leshukovreltio-ui-coemanpreet_hayerandrew.borovin.reltioamith.ravuru

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:bundle.js AI (source-diff): bundle.js is a standard webpack bundle; long strings are MUI icon require lists, not obfuscated payloads. ai
npm-metadata no-description AI (npm-metadata): Consistent pattern across 1353 versions of this org-internal package. ai
provenance no-provenance AI (provenance): Org-internal package; no provenance is consistent across all versions. ai
bogus-package bogus-package AI (bogus-package): Internal enterprise module; sparse metadata is consistent across all 1353 versions of this org's packages. ai
phantom-deps phantom-dep:graphology-layout AI (phantom-deps): Graph layout lib; referenced in config, stable FP. ai
phantom-deps phantom-dep:graphology-operators AI (phantom-deps): Graph operators lib; referenced in config, stable FP. ai
phantom-deps phantom-dep:graphology-shortest-path AI (phantom-deps): Graph algorithm lib; referenced in config, stable FP. ai
phantom-deps phantom-dep:sigma AI (phantom-deps): Graph visualization lib; likely re-exported or used via config/peer, not directly imported. ai
phantom-deps phantom-dep:@reltio/profile AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. ai
phantom-deps phantom-dep:@reltio/components AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. ai
phantom-deps phantom-dep:@reltio/mdm-module AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. ai
phantom-deps phantom-dep:@reltio/mdm-sdk AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. ai
phantom-deps phantom-dep:graphology AI (phantom-deps): Core graph lib; referenced in config, stable false positive for this package. ai
phantom-deps phantom-dep:graphology-types AI (phantom-deps): Type-only dep; not directly imported but used in config/types. ai
phantom-deps phantom-dep:@react-sigma/core AI (phantom-deps): Sigma React wrapper; referenced in config, stable FP for this package. ai

Versions (showing 51 of 94)

View all versions
Version Deps Published
1.4.2335 11 / 0
1.4.2334 11 / 0
1.4.2333 11 / 0
1.4.2332 11 / 0
1.4.2331 11 / 0
1.4.2330 11 / 0
1.4.2329 11 / 0
1.4.2328 11 / 0
1.4.2323 11 / 0
1.4.2322 11 / 0
1.4.2319 11 / 0
1.4.2317 11 / 0
1.4.2316 11 / 0
1.4.2315 11 / 0
1.4.2314 11 / 0
1.4.2313 11 / 0
1.4.2312 11 / 0
1.4.2311 11 / 0
1.4.2310 11 / 0
1.4.2309 11 / 0
1.4.2308 11 / 0
1.4.2307 11 / 0
1.4.2306 11 / 0
1.4.2304 11 / 0
1.4.2303 11 / 0
1.4.2302 11 / 0
1.4.2301 11 / 0
1.4.2298 11 / 0
1.4.2295 11 / 0
1.4.2294 11 / 0
1.4.2293 11 / 0
1.4.2288 11 / 0
1.4.2283 11 / 0
1.4.2281 11 / 0
1.4.2280 11 / 0
1.4.2278 11 / 0
1.4.2275 11 / 0
1.4.2274 11 / 0
1.4.2273 11 / 0
1.4.2270 11 / 0
1.4.2269 11 / 0
1.4.2268 11 / 0
1.4.2266 11 / 0
1.4.2265 11 / 0
1.4.2264 11 / 0
1.4.2263 11 / 0
1.4.2261 11 / 0
1.4.2260 11 / 0
1.4.2259 11 / 0
1.4.2258 11 / 0
1.4.2257 11 / 0

v1.4.2335

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2334

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2333

2 findings
HIGH Long encoded string in modified file: bundle.js source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2332

2 findings
HIGH Long encoded string in modified file: bundle.js source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2331

2 findings
HIGH Long encoded string in modified file: bundle.js source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2330

2 findings
HIGH Long encoded string in modified file: bundle.js source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2329

2 findings
HIGH Long encoded string in modified file: bundle.js source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2328

2 findings
HIGH Long encoded string in modified file: bundle.js source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2323

2 findings
HIGH Long encoded string in modified file: bundle.js source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2322

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2319

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2317

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2316

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2315

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2314

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2313

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2312

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2311

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2310

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2309

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2308

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2307

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2306

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2304

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2303

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2302

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2301

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2298

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2295

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2294

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2293

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2288

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2283

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2281

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2280

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2278

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2275

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2274

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2273

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2270

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2269

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2268

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2266

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2265

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2264

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2263

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2261

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2260

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2259

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2258

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2257

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.