@reltio/graph
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:bundle.js | AI (source-diff): bundle.js is a standard webpack bundle; long strings are MUI icon require lists, not obfuscated payloads. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent pattern across 1353 versions of this org-internal package. | ai | |
| provenance | no-provenance | AI (provenance): Org-internal package; no provenance is consistent across all versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal enterprise module; sparse metadata is consistent across all 1353 versions of this org's packages. | ai | |
| phantom-deps | phantom-dep:graphology-layout | AI (phantom-deps): Graph layout lib; referenced in config, stable FP. | ai | |
| phantom-deps | phantom-dep:graphology-operators | AI (phantom-deps): Graph operators lib; referenced in config, stable FP. | ai | |
| phantom-deps | phantom-dep:graphology-shortest-path | AI (phantom-deps): Graph algorithm lib; referenced in config, stable FP. | ai | |
| phantom-deps | phantom-dep:sigma | AI (phantom-deps): Graph visualization lib; likely re-exported or used via config/peer, not directly imported. | ai | |
| phantom-deps | phantom-dep:@reltio/profile | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:@reltio/components | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-module | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-sdk | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:graphology | AI (phantom-deps): Core graph lib; referenced in config, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:graphology-types | AI (phantom-deps): Type-only dep; not directly imported but used in config/types. | ai | |
| phantom-deps | phantom-dep:@react-sigma/core | AI (phantom-deps): Sigma React wrapper; referenced in config, stable FP for this package. | ai |
Versions (showing 19 of 319)
| Version | Deps | Published |
|---|---|---|
| 1.4.1981 | 11 / 0 | |
| 1.4.1980 | 11 / 0 | |
| 1.4.1979 | 11 / 0 | |
| 1.4.1978 | 11 / 0 | |
| 1.4.1977 | 11 / 0 | |
| 1.4.1976 | 11 / 0 | |
| 1.4.1975 | 11 / 0 | |
| 1.4.1974 | 11 / 0 | |
| 1.4.1973 | 11 / 0 | |
| 1.4.1972 | 11 / 0 | |
| 1.4.1971 | 11 / 0 | |
| 1.4.1970 | 11 / 0 | |
| 1.4.1969 | 11 / 0 | |
| 1.4.1968 | 11 / 0 | |
| 1.4.1967 | 11 / 0 | |
| 1.4.1966 | 11 / 0 | |
| 1.4.1965 | 11 / 0 | |
| 1.4.1964 | 11 / 0 | |
| 1.4.1963 | 11 / 0 |
v1.4.1981
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1980
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1979
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1978
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1977
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1976
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1975
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1974
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1973
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1972
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1971
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1970
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1969
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1968
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1967
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1966
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1965
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1964
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1963
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.