@reltio/members
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires in bundle.js webpack output; standard bundler pattern for this org's packages. | ai | |
| dependencies | unvetted-dep:@reltio/mdm-sdk | AI (dependencies): Same-org @reltio scoped dependency; consistent pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@reltio/mdm-module | AI (dependencies): Same-org @reltio scoped dependency; consistent pattern across all versions of this package. | ai | |
| phantom-deps | phantom-dep:@reltio/components | AI (phantom-deps): Same org scope; likely re-exported or used indirectly via bundle.js. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal enterprise scoped package; missing metadata is expected for org-internal components. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-module | AI (phantom-deps): Same org scope; likely re-exported or used indirectly via bundle.js. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent pattern across @reltio/ org packages; not a malware indicator. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-sdk | AI (phantom-deps): Same org scope; likely re-exported or used indirectly via bundle.js. | ai |
Versions (showing 51 of 106)
| Version | Deps | Published |
|---|---|---|
| 1.4.127 | 3 / 0 | |
| 1.4.126 | 3 / 0 | |
| 1.4.124 | 3 / 0 | |
| 1.4.123 | 3 / 0 | |
| 1.4.122 | 3 / 0 | |
| 1.4.121 | 3 / 0 | |
| 1.4.120 | 3 / 0 | |
| 1.4.119 | 3 / 0 | |
| 1.4.118 | 3 / 0 | |
| 1.4.117 | 3 / 0 | |
| 1.4.116 | 3 / 0 | |
| 1.4.115 | 3 / 0 | |
| 1.4.114 | 3 / 0 | |
| 1.4.113 | 3 / 0 | |
| 1.4.112 | 3 / 0 | |
| 1.4.111 | 3 / 0 | |
| 1.4.109 | 3 / 0 | |
| 1.4.108 | 3 / 0 | |
| 1.4.107 | 3 / 0 | |
| 1.4.106 | 3 / 0 | |
| 1.4.105 | 3 / 0 | |
| 1.4.104 | 3 / 0 | |
| 1.4.103 | 3 / 0 | |
| 1.4.102 | 3 / 0 | |
| 1.4.101 | 3 / 0 | |
| 1.4.100 | 3 / 0 | |
| 1.4.99 | 3 / 0 | |
| 1.4.98 | 3 / 0 | |
| 1.4.97 | 3 / 0 | |
| 1.4.96 | 3 / 0 | |
| 1.4.95 | 3 / 0 | |
| 1.4.94 | 3 / 0 | |
| 1.4.93 | 3 / 0 | |
| 1.4.92 | 3 / 0 | |
| 1.4.91 | 3 / 0 | |
| 1.4.90 | 3 / 0 | |
| 1.4.89 | 3 / 0 | |
| 1.4.88 | 3 / 0 | |
| 1.4.87 | 3 / 0 | |
| 1.4.86 | 3 / 0 | |
| 1.4.85 | 3 / 0 | |
| 1.4.84 | 3 / 0 | |
| 1.4.83 | 3 / 0 | |
| 1.4.82 | 3 / 0 | |
| 1.4.81 | 3 / 0 | |
| 1.4.80 | 3 / 0 | |
| 1.4.79 | 3 / 0 | |
| 1.4.78 | 3 / 0 | |
| 1.4.77 | 3 / 0 | |
| 1.4.76 | 3 / 0 | |
| 1.4.75 | 3 / 0 |
v1.4.127
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.126
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.124
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.123
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.122
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.121
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.120
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.119
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.118
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.117
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.116
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.