@reltio/mdm-module
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Internal enterprise scoped package; missing metadata is a consistent pattern across its 2000+ versions, not a spam indicator. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across all versions of this internal enterprise package; not a malice signal. | ai | |
| provenance | no-provenance | AI (provenance): No provenance across all versions; internal package pattern, not a risk signal here. | ai |
Versions (showing 51 of 290)
| Version | Deps | Published |
|---|---|---|
| 1.4.2100 | 5 / 0 | |
| 1.4.2098 | 5 / 0 | |
| 1.4.2097 | 5 / 0 | |
| 1.4.2096 | 5 / 0 | |
| 1.4.2095 | 5 / 0 | |
| 1.4.2094 | 5 / 0 | |
| 1.4.2093 | 5 / 0 | |
| 1.4.2092 | 5 / 0 | |
| 1.4.2090 | 5 / 0 | |
| 1.4.2089 | 5 / 0 | |
| 1.4.2088 | 5 / 0 | |
| 1.4.2087 | 5 / 0 | |
| 1.4.2086 | 5 / 0 | |
| 1.4.2085 | 5 / 0 | |
| 1.4.2084 | 5 / 0 | |
| 1.4.2083 | 5 / 0 | |
| 1.4.2082 | 5 / 0 | |
| 1.4.2081 | 5 / 0 | |
| 1.4.2080 | 5 / 0 | |
| 1.4.2079 | 5 / 0 | |
| 1.4.2078 | 5 / 0 | |
| 1.4.2077 | 5 / 0 | |
| 1.4.2076 | 5 / 0 | |
| 1.4.2075 | 5 / 0 | |
| 1.4.2074 | 5 / 0 | |
| 1.4.2073 | 5 / 0 | |
| 1.4.2072 | 5 / 0 | |
| 1.4.2071 | 5 / 0 | |
| 1.4.2070 | 5 / 0 | |
| 1.4.2069 | 5 / 0 | |
| 1.4.2068 | 5 / 0 | |
| 1.4.2067 | 5 / 0 | |
| 1.4.2066 | 5 / 0 | |
| 1.4.2065 | 5 / 0 | |
| 1.4.2064 | 5 / 0 | |
| 1.4.2063 | 5 / 0 | |
| 1.4.2062 | 5 / 0 | |
| 1.4.2059 | 5 / 0 | |
| 1.4.2058 | 5 / 0 | |
| 1.4.2057 | 5 / 0 | |
| 1.4.2056 | 5 / 0 | |
| 1.4.2055 | 5 / 0 | |
| 1.4.2054 | 5 / 0 | |
| 1.4.2053 | 5 / 0 | |
| 1.4.2052 | 5 / 0 | |
| 1.4.2051 | 5 / 0 | |
| 1.4.2050 | 5 / 0 | |
| 1.4.2049 | 5 / 0 | |
| 1.4.2048 | 5 / 0 | |
| 1.4.2047 | 5 / 0 | |
| 1.4.2046 | 5 / 0 |
v1.4.2100
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2098
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2097
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2096
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2095
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2094
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.