@reltio/graph
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:bundle.js | AI (source-diff): bundle.js is a standard webpack bundle; long strings are MUI icon require lists, not obfuscated payloads. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent pattern across 1353 versions of this org-internal package. | ai | |
| provenance | no-provenance | AI (provenance): Org-internal package; no provenance is consistent across all versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal enterprise module; sparse metadata is consistent across all 1353 versions of this org's packages. | ai | |
| phantom-deps | phantom-dep:graphology-layout | AI (phantom-deps): Graph layout lib; referenced in config, stable FP. | ai | |
| phantom-deps | phantom-dep:graphology-operators | AI (phantom-deps): Graph operators lib; referenced in config, stable FP. | ai | |
| phantom-deps | phantom-dep:graphology-shortest-path | AI (phantom-deps): Graph algorithm lib; referenced in config, stable FP. | ai | |
| phantom-deps | phantom-dep:sigma | AI (phantom-deps): Graph visualization lib; likely re-exported or used via config/peer, not directly imported. | ai | |
| phantom-deps | phantom-dep:@reltio/profile | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:@reltio/components | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-module | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-sdk | AI (phantom-deps): Same org scope; stable FP for internal monorepo-style package. | ai | |
| phantom-deps | phantom-dep:graphology | AI (phantom-deps): Core graph lib; referenced in config, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:graphology-types | AI (phantom-deps): Type-only dep; not directly imported but used in config/types. | ai | |
| phantom-deps | phantom-dep:@react-sigma/core | AI (phantom-deps): Sigma React wrapper; referenced in config, stable FP for this package. | ai |
Versions (showing 100 of 319)
| Version | Deps | Published |
|---|---|---|
| 1.4.2191 | 11 / 0 | |
| 1.4.2189 | 11 / 0 | |
| 1.4.2187 | 11 / 0 | |
| 1.4.2186 | 11 / 0 | |
| 1.4.2185 | 11 / 0 | |
| 1.4.2184 | 11 / 0 | |
| 1.4.2183 | 11 / 0 | |
| 1.4.2180 | 11 / 0 | |
| 1.4.2178 | 11 / 0 | |
| 1.4.2177 | 11 / 0 | |
| 1.4.2176 | 11 / 0 | |
| 1.4.2175 | 11 / 0 | |
| 1.4.2174 | 11 / 0 | |
| 1.4.2173 | 11 / 0 | |
| 1.4.2172 | 11 / 0 | |
| 1.4.2171 | 11 / 0 | |
| 1.4.2170 | 11 / 0 | |
| 1.4.2169 | 11 / 0 | |
| 1.4.2168 | 11 / 0 | |
| 1.4.2167 | 11 / 0 | |
| 1.4.2166 | 11 / 0 | |
| 1.4.2165 | 11 / 0 | |
| 1.4.2164 | 11 / 0 | |
| 1.4.2163 | 11 / 0 | |
| 1.4.2162 | 11 / 0 | |
| 1.4.2161 | 11 / 0 | |
| 1.4.2160 | 11 / 0 | |
| 1.4.2159 | 11 / 0 | |
| 1.4.2158 | 11 / 0 | |
| 1.4.2157 | 11 / 0 | |
| 1.4.2156 | 11 / 0 | |
| 1.4.2155 | 11 / 0 | |
| 1.4.2154 | 11 / 0 | |
| 1.4.2153 | 11 / 0 | |
| 1.4.2150 | 11 / 0 | |
| 1.4.2149 | 11 / 0 | |
| 1.4.2148 | 11 / 0 | |
| 1.4.2147 | 11 / 0 | |
| 1.4.2146 | 11 / 0 | |
| 1.4.2145 | 11 / 0 | |
| 1.4.2144 | 11 / 0 | |
| 1.4.2143 | 11 / 0 | |
| 1.4.2142 | 11 / 0 | |
| 1.4.2141 | 11 / 0 | |
| 1.4.2140 | 11 / 0 | |
| 1.4.2139 | 11 / 0 | |
| 1.4.2138 | 11 / 0 | |
| 1.4.2137 | 11 / 0 | |
| 1.4.2136 | 11 / 0 | |
| 1.4.2135 | 11 / 0 | |
| 1.4.2134 | 11 / 0 | |
| 1.4.2133 | 11 / 0 | |
| 1.4.2132 | 11 / 0 | |
| 1.4.2131 | 11 / 0 | |
| 1.4.2130 | 11 / 0 | |
| 1.4.2129 | 11 / 0 | |
| 1.4.2128 | 11 / 0 | |
| 1.4.2127 | 11 / 0 | |
| 1.4.2126 | 11 / 0 | |
| 1.4.2125 | 11 / 0 | |
| 1.4.2124 | 11 / 0 | |
| 1.4.2123 | 11 / 0 | |
| 1.4.2122 | 11 / 0 | |
| 1.4.2121 | 11 / 0 | |
| 1.4.2120 | 11 / 0 | |
| 1.4.2119 | 11 / 0 | |
| 1.4.2118 | 11 / 0 | |
| 1.4.2117 | 11 / 0 | |
| 1.4.2116 | 11 / 0 | |
| 1.4.2115 | 11 / 0 | |
| 1.4.2114 | 11 / 0 | |
| 1.4.2113 | 11 / 0 | |
| 1.4.2112 | 11 / 0 | |
| 1.4.2111 | 11 / 0 | |
| 1.4.2110 | 11 / 0 | |
| 1.4.2109 | 11 / 0 | |
| 1.4.2108 | 11 / 0 | |
| 1.4.2107 | 11 / 0 | |
| 1.4.2106 | 11 / 0 | |
| 1.4.2105 | 11 / 0 | |
| 1.4.2104 | 11 / 0 | |
| 1.4.2103 | 11 / 0 | |
| 1.4.2102 | 11 / 0 | |
| 1.4.2101 | 11 / 0 | |
| 1.4.2100 | 11 / 0 | |
| 1.4.2099 | 11 / 0 | |
| 1.4.2098 | 11 / 0 | |
| 1.4.2097 | 11 / 0 | |
| 1.4.2096 | 11 / 0 | |
| 1.4.2095 | 11 / 0 | |
| 1.4.2094 | 11 / 0 | |
| 1.4.2093 | 11 / 0 | |
| 1.4.2092 | 11 / 0 | |
| 1.4.2091 | 11 / 0 | |
| 1.4.2090 | 11 / 0 | |
| 1.4.2089 | 11 / 0 | |
| 1.4.2088 | 11 / 0 | |
| 1.4.2087 | 11 / 0 | |
| 1.4.2086 | 11 / 0 | |
| 1.4.2085 | 11 / 0 |
v1.4.2175
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2174
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2173
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2172
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2171
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2170
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2169
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2168
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2167
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2166
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2165
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2164
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2163
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2162
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2161
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2160
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2159
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2158
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2157
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2156
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2155
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2154
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2153
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2150
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2149
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2148
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2147
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2146
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2145
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2144
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2143
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2142
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2141
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2140
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2139
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2138
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2137
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2136
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2135
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2134
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2133
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2132
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2131
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2130
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2129
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2128
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2127
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2126
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2125
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2124
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2123
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2122
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2121
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2120
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2119
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2118
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2117
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2116
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2115
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2114
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2113
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2112
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2111
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2110
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2109
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2108
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2107
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2106
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2105
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2104
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2103
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2102
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2101
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2100
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2099
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2098
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2097
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2096
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2095
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2094
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2093
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2092
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2091
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2090
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2089
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2088
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2087
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2086
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2085
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.