@reltio/ria
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:ria-plugin.js | AI (source-diff): Webpack-bundled minified UI code (emotion/CSS-in-JS), not real obfuscation. | ai | |
| source-diff | net-exec-file:ria-plugin.js | AI (source-diff): Bundled frontend library, network+eval patterns are standard bundler/runtime code. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-module | AI (phantom-deps): Same-org scoped dep in a monorepo/microfrontend; stable false positive. | ai | |
| phantom-deps | phantom-dep:@reltio/sources | AI (phantom-deps): Same-org scoped dep in a monorepo/microfrontend; stable false positive. | ai | |
| phantom-deps | phantom-dep:@reltio/dashboard | AI (phantom-deps): Same-org scoped dep in a monorepo/microfrontend; stable false positive. | ai | |
| phantom-deps | phantom-dep:@reltio/components | AI (phantom-deps): Same-org scoped dep in a monorepo/microfrontend; stable false positive. | ai | |
| typosquat | typosquat.levenshtein:koa | AI (typosquat): Scoped @reltio org package; Levenshtein match to 'koa' is a false positive for this namespace. | ai | |
| phantom-deps | phantom-dep:react-markdown | AI (phantom-deps): Config-referenced dep in bundled package; stable false positive. | ai | |
| phantom-deps | phantom-dep:rehype-raw | AI (phantom-deps): Config-referenced dep in bundled package; stable false positive. | ai | |
| phantom-deps | phantom-dep:rehype-sanitize | AI (phantom-deps): Config-referenced dep in bundled package; stable false positive. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Config-referenced dep in bundled package; stable false positive. | ai | |
| phantom-deps | phantom-dep:swr | AI (phantom-deps): Config-referenced dep in bundled package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-sdk | AI (phantom-deps): Same-org scoped dep in a monorepo/microfrontend; stable false positive. | ai |
Versions (showing 51 of 179)
| Version | Deps | Published |
|---|---|---|
| 1.4.576 | 10 / 0 | |
| 1.4.575 | 10 / 0 | |
| 1.4.573 | 10 / 0 | |
| 1.4.572 | 10 / 0 | |
| 1.4.571 | 10 / 0 | |
| 1.4.570 | 10 / 0 | |
| 1.4.569 | 10 / 0 | |
| 1.4.568 | 10 / 0 | |
| 1.4.567 | 10 / 0 | |
| 1.4.566 | 10 / 0 | |
| 1.4.565 | 10 / 0 | |
| 1.4.564 | 10 / 0 | |
| 1.4.563 | 10 / 0 | |
| 1.4.562 | 10 / 0 | |
| 1.4.561 | 10 / 0 | |
| 1.4.560 | 10 / 0 | |
| 1.4.559 | 10 / 0 | |
| 1.4.557 | 10 / 0 | |
| 1.4.556 | 10 / 0 | |
| 1.4.555 | 10 / 0 | |
| 1.4.554 | 10 / 0 | |
| 1.4.553 | 10 / 0 | |
| 1.4.552 | 10 / 0 | |
| 1.4.551 | 10 / 0 | |
| 1.4.550 | 10 / 0 | |
| 1.4.549 | 10 / 0 | |
| 1.4.548 | 10 / 0 | |
| 1.4.547 | 10 / 0 | |
| 1.4.546 | 10 / 0 | |
| 1.4.545 | 10 / 0 | |
| 1.4.544 | 10 / 0 | |
| 1.4.543 | 10 / 0 | |
| 1.4.542 | 10 / 0 | |
| 1.4.541 | 10 / 0 | |
| 1.4.540 | 10 / 0 | |
| 1.4.539 | 10 / 0 | |
| 1.4.538 | 10 / 0 | |
| 1.4.537 | 10 / 0 | |
| 1.4.536 | 10 / 0 | |
| 1.4.535 | 10 / 0 | |
| 1.4.534 | 10 / 0 | |
| 1.4.533 | 10 / 0 | |
| 1.4.516 | 10 / 0 | |
| 1.4.506 | 7 / 0 | |
| 1.4.505 | 7 / 0 | |
| 1.4.504 | 7 / 0 | |
| 1.4.503 | 7 / 0 | |
| 1.4.502 | 7 / 0 | |
| 1.4.501 | 7 / 0 | |
| 1.4.500 | 7 / 0 | |
| 1.4.499 | 7 / 0 |
v1.4.576
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.575
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.573
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.572
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.571
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.570
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.569
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.568
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.567
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.566
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.565
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.564
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.544
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (egorshkov) than the most recent previously approved version (reltio-ui-coe) on 2026-04-28, but egorshkov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.543
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (egorshkov) than the most recent previously approved version (reltio-ui-coe) on 2026-04-28, but egorshkov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.542
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (egorshkov) than the most recent previously approved version (reltio-ui-coe) on 2026-04-23, but egorshkov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.541
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (egorshkov) than the most recent previously approved version (reltio-ui-coe) on 2026-04-23, but egorshkov is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.516
4 findingsThis version was published by a different npm account than previous versions on 2026-02-05. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.506
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vitaly.gerasev) than the most recent previously approved version (alexander.kirsanov) on 2025-12-10, but vitaly.gerasev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.505
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vitaly.gerasev) than the most recent previously approved version (alexander.kirsanov) on 2025-12-04, but vitaly.gerasev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.504
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vitaly.gerasev) than the most recent previously approved version (alexander.kirsanov) on 2025-12-04, but vitaly.gerasev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.503
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vitaly.gerasev) than the most recent previously approved version (alexander.kirsanov) on 2025-12-04, but vitaly.gerasev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.502
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vitaly.gerasev) than the most recent previously approved version (alexander.kirsanov) on 2025-12-04, but vitaly.gerasev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.501
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vitaly.gerasev) than the most recent previously approved version (alexander.kirsanov) on 2025-12-02, but vitaly.gerasev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.500
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vitaly.gerasev) than the most recent previously approved version (alexander.kirsanov) on 2025-11-28, but vitaly.gerasev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.499
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vitaly.gerasev) than the most recent previously approved version (alexander.kirsanov) on 2025-11-28, but vitaly.gerasev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.