← Home

@reltio/search

100
Versions
SEE LICENSE IN LICENSE FILE
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

egorshkovvitaly.gerasevalexander.leshukovreltio-ui-coemanpreet_hayerandrew.borovin.reltioamith.ravuru

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): New publisher reltio-ui-coe is an org CI account with 811 approved packages; consistent with legitimate org-level transition. ai
bogus-package bogus-package AI (bogus-package): Internal org package with 2250+ versions; sparse metadata is consistent across all releases. ai
npm-metadata no-description AI (npm-metadata): Stable pattern across all versions of this internal org package. ai
provenance no-provenance AI (provenance): No provenance across all versions; consistent org-wide pattern. ai
phantom-deps phantom-dep:query-string AI (phantom-deps): Same monorepo pattern; stable false positive for this package. ai
phantom-deps phantom-dep:react-window AI (phantom-deps): Same monorepo pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@reltio/mdm-sdk AI (phantom-deps): Same org scope; stable false positive for this package. ai
phantom-deps phantom-dep:reselect AI (phantom-deps): Org monorepo pattern; deps declared for consumers, not directly imported in bundle. ai
phantom-deps phantom-dep:@reltio/mdm-module AI (phantom-deps): Same org scope; stable false positive for this package. ai
phantom-deps phantom-dep:redux-dynamic-modules-react AI (phantom-deps): Same monorepo pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@reltio/components AI (phantom-deps): Same org scope; stable false positive for this package. ai
phantom-deps phantom-dep:decimal.js AI (phantom-deps): Same monorepo pattern; stable false positive for this package. ai
phantom-deps phantom-dep:redux-saga AI (phantom-deps): Same monorepo pattern; stable false positive for this package. ai
phantom-deps phantom-dep:memoize-one AI (phantom-deps): Same monorepo pattern; stable false positive for this package. ai

Versions (showing 100 of 383)

Version Deps Published
1.4.2253 10 / 0
1.4.2252 10 / 0
1.4.2251 10 / 0
1.4.2250 10 / 0
1.4.2249 10 / 0
1.4.2248 10 / 0
1.4.2247 10 / 0
1.4.2246 10 / 0
1.4.2245 10 / 0
1.4.2244 10 / 0
1.4.2243 10 / 0
1.4.2242 10 / 0
1.4.2241 10 / 0
1.4.2240 10 / 0
1.4.2239 10 / 0
1.4.2238 10 / 0
1.4.2237 10 / 0
1.4.2236 10 / 0
1.4.2235 10 / 0
1.4.2234 10 / 0
1.4.2233 10 / 0
1.4.2232 10 / 0
1.4.2231 10 / 0
1.4.2230 10 / 0
1.4.2229 10 / 0
1.4.2228 10 / 0
1.4.2227 10 / 0
1.4.2226 10 / 0
1.4.2225 10 / 0
1.4.2224 10 / 0
1.4.2223 10 / 0
1.4.2222 10 / 0
1.4.2221 10 / 0
1.4.2220 10 / 0
1.4.2219 10 / 0
1.4.2218 10 / 0
1.4.2217 10 / 0
1.4.2216 10 / 0
1.4.2215 10 / 0
1.4.2214 10 / 0
1.4.2213 10 / 0
1.4.2212 10 / 0
1.4.2211 10 / 0
1.4.2210 10 / 0
1.4.2209 10 / 0
1.4.2208 10 / 0
1.4.2207 10 / 0
1.4.2206 10 / 0
1.4.2205 10 / 0
1.4.2204 10 / 0
1.4.2203 10 / 0
1.4.2202 10 / 0
1.4.2201 10 / 0
1.4.2200 10 / 0
1.4.2199 10 / 0
1.4.2198 10 / 0
1.4.2197 10 / 0
1.4.2196 10 / 0
1.4.2195 10 / 0
1.4.2194 10 / 0
1.4.2193 10 / 0
1.4.2192 10 / 0
1.4.2191 10 / 0
1.4.2190 10 / 0
1.4.2189 10 / 0
1.4.2188 10 / 0
1.4.2187 10 / 0
1.4.2186 10 / 0
1.4.2185 10 / 0
1.4.2184 10 / 0
1.4.2183 10 / 0
1.4.2182 10 / 0
1.4.2181 10 / 0
1.4.2180 10 / 0
1.4.2179 10 / 0
1.4.2178 10 / 0
1.4.2177 10 / 0
1.4.2176 10 / 0
1.4.2175 10 / 0
1.4.2174 10 / 0
1.4.2173 10 / 0
1.4.2172 10 / 0
1.4.2171 10 / 0
1.4.2170 10 / 0
1.4.2169 10 / 0
1.4.2168 10 / 0
1.4.2167 10 / 0
1.4.2166 10 / 0
1.4.2165 10 / 0
1.4.2164 10 / 0
1.4.2163 10 / 0
1.4.2162 10 / 0
1.4.2161 10 / 0
1.4.2160 10 / 0
1.4.2159 10 / 0
1.4.2158 10 / 0
1.4.2155 10 / 0
1.4.2154 10 / 0
1.4.2153 10 / 0
1.4.2152 10 / 0
Showing 100 of 383 Next page →

v1.4.2180

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2179

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2178

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2177

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2176

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2175

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2174

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2173

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2172

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2171

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2170

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2169

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2168

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2167

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2166

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2165

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2164

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2163

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2162

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2161

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2160

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2159

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2158

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2155

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2154

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2153

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2152

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.