@reltio/graph
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:bundle.js | AI (source-diff): bundle.js is a standard webpack bundle; long strings are MUI icon require lists, not obfuscated payloads. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent pattern across 1353 versions of this org-internal package. | ai | |
| provenance | no-provenance | AI (provenance): Org-internal package; no provenance is consistent across all versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal enterprise module; sparse metadata is consistent across all 1353 versions of this org's packages. | ai | |
| phantom-deps | phantom-dep:graphology-layout | AI (phantom-deps): Graph layout lib; referenced in config, stable FP. | ai | |
| phantom-deps | phantom-dep:graphology-operators | AI (phantom-deps): Graph operators lib; referenced in config, stable FP. | ai | |
| phantom-deps | phantom-dep:graphology-shortest-path | AI (phantom-deps): Graph algorithm lib; referenced in config, stable FP. | ai | |
| phantom-deps | phantom-dep:sigma | AI (phantom-deps): Graph visualization lib; likely re-exported or used via config/peer, not directly imported. | ai | |
| phantom-deps | phantom-dep:@reltio/profile | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:@reltio/components | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-module | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-sdk | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:graphology | AI (phantom-deps): Core graph lib; referenced in config, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:graphology-types | AI (phantom-deps): Type-only dep; not directly imported but used in config/types. | ai | |
| phantom-deps | phantom-dep:@react-sigma/core | AI (phantom-deps): Sigma React wrapper; referenced in config, stable FP for this package. | ai |
Versions (showing 100 of 319)
| Version | Deps | Published |
|---|---|---|
| 1.4.2084 | 11 / 0 | |
| 1.4.2083 | 11 / 0 | |
| 1.4.2082 | 11 / 0 | |
| 1.4.2081 | 11 / 0 | |
| 1.4.2080 | 11 / 0 | |
| 1.4.2079 | 11 / 0 | |
| 1.4.2078 | 11 / 0 | |
| 1.4.2077 | 11 / 0 | |
| 1.4.2076 | 11 / 0 | |
| 1.4.2075 | 11 / 0 | |
| 1.4.2074 | 11 / 0 | |
| 1.4.2073 | 11 / 0 | |
| 1.4.2072 | 11 / 0 | |
| 1.4.2071 | 11 / 0 | |
| 1.4.2070 | 11 / 0 | |
| 1.4.2069 | 11 / 0 | |
| 1.4.2068 | 11 / 0 | |
| 1.4.2067 | 11 / 0 | |
| 1.4.2066 | 11 / 0 | |
| 1.4.2065 | 11 / 0 | |
| 1.4.2064 | 11 / 0 | |
| 1.4.2063 | 11 / 0 | |
| 1.4.2062 | 11 / 0 | |
| 1.4.2061 | 11 / 0 | |
| 1.4.2060 | 11 / 0 | |
| 1.4.2059 | 11 / 0 | |
| 1.4.2058 | 11 / 0 | |
| 1.4.2057 | 11 / 0 | |
| 1.4.2056 | 11 / 0 | |
| 1.4.2055 | 11 / 0 | |
| 1.4.2054 | 11 / 0 | |
| 1.4.2053 | 11 / 0 | |
| 1.4.2052 | 11 / 0 | |
| 1.4.2051 | 11 / 0 | |
| 1.4.2050 | 11 / 0 | |
| 1.4.2049 | 11 / 0 | |
| 1.4.2048 | 11 / 0 | |
| 1.4.2047 | 11 / 0 | |
| 1.4.2046 | 11 / 0 | |
| 1.4.2045 | 11 / 0 | |
| 1.4.2043 | 11 / 0 | |
| 1.4.2042 | 11 / 0 | |
| 1.4.2041 | 11 / 0 | |
| 1.4.2040 | 11 / 0 | |
| 1.4.2038 | 11 / 0 | |
| 1.4.2037 | 11 / 0 | |
| 1.4.2036 | 11 / 0 | |
| 1.4.2035 | 11 / 0 | |
| 1.4.2034 | 11 / 0 | |
| 1.4.2033 | 11 / 0 | |
| 1.4.2032 | 11 / 0 | |
| 1.4.2031 | 11 / 0 | |
| 1.4.2030 | 11 / 0 | |
| 1.4.2029 | 11 / 0 | |
| 1.4.2028 | 11 / 0 | |
| 1.4.2027 | 11 / 0 | |
| 1.4.2026 | 11 / 0 | |
| 1.4.2025 | 11 / 0 | |
| 1.4.2024 | 11 / 0 | |
| 1.4.2023 | 11 / 0 | |
| 1.4.2022 | 11 / 0 | |
| 1.4.2021 | 11 / 0 | |
| 1.4.2020 | 11 / 0 | |
| 1.4.2019 | 11 / 0 | |
| 1.4.2018 | 11 / 0 | |
| 1.4.2017 | 11 / 0 | |
| 1.4.2016 | 11 / 0 | |
| 1.4.2015 | 11 / 0 | |
| 1.4.2014 | 11 / 0 | |
| 1.4.2013 | 11 / 0 | |
| 1.4.2012 | 11 / 0 | |
| 1.4.2011 | 11 / 0 | |
| 1.4.2010 | 11 / 0 | |
| 1.4.2009 | 11 / 0 | |
| 1.4.2008 | 11 / 0 | |
| 1.4.2007 | 11 / 0 | |
| 1.4.2006 | 11 / 0 | |
| 1.4.2005 | 11 / 0 | |
| 1.4.2004 | 11 / 0 | |
| 1.4.2003 | 11 / 0 | |
| 1.4.2002 | 11 / 0 | |
| 1.4.2001 | 11 / 0 | |
| 1.4.2000 | 11 / 0 | |
| 1.4.1999 | 11 / 0 | |
| 1.4.1998 | 11 / 0 | |
| 1.4.1997 | 11 / 0 | |
| 1.4.1996 | 11 / 0 | |
| 1.4.1995 | 11 / 0 | |
| 1.4.1994 | 11 / 0 | |
| 1.4.1993 | 11 / 0 | |
| 1.4.1992 | 11 / 0 | |
| 1.4.1991 | 11 / 0 | |
| 1.4.1990 | 11 / 0 | |
| 1.4.1989 | 11 / 0 | |
| 1.4.1987 | 11 / 0 | |
| 1.4.1986 | 11 / 0 | |
| 1.4.1985 | 11 / 0 | |
| 1.4.1984 | 11 / 0 | |
| 1.4.1983 | 11 / 0 | |
| 1.4.1982 | 11 / 0 |
v1.4.2084
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2083
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2082
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2081
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2080
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2079
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2078
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2077
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2076
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2075
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2074
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2073
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2072
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2071
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2070
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2069
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2068
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2067
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2066
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2065
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2064
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2063
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2062
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2061
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2060
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2059
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2058
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2057
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2056
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2055
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2054
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2053
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2052
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2051
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2050
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2049
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2048
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2047
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2046
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2045
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2043
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2042
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2041
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2040
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2038
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2037
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2036
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2035
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2034
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2033
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2032
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2031
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2030
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2029
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2028
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2027
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2026
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2025
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2024
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2023
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2022
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2021
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2020
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2019
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2018
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2017
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2016
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2015
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2014
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2013
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2012
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2011
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2010
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2009
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2008
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2007
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2006
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2005
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2004
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2003
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2002
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2001
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2000
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1999
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1998
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1997
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1996
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1995
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1994
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1993
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1992
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1991
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1990
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1989
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1987
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1986
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1985
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1984
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1983
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1982
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.