@reltio/segmentation
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Internal org package; missing metadata is consistent across all 532 versions, not a spam indicator. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable pattern across all versions of this internal org package. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-sdk | AI (phantom-deps): Same-org bundled dependency; phantom-dep heuristic unreliable for bundled packages. | ai | |
| phantom-deps | phantom-dep:@reltio/mdm-module | AI (phantom-deps): Same-org bundled dependency; phantom-dep heuristic unreliable for bundled packages. | ai | |
| phantom-deps | phantom-dep:@reltio/components | AI (phantom-deps): Same-org bundled dependency; phantom-dep heuristic unreliable for bundled packages. | ai | |
| phantom-deps | phantom-dep:@reltio-lab/utils | AI (phantom-deps): Referenced in config files per finding; stable false positive for this bundled package. | ai | |
| phantom-deps | phantom-dep:rrule | AI (phantom-deps): Referenced in config files per finding; stable false positive for this bundled package. | ai |
Versions (showing 51 of 540)
| Version | Deps | Published |
|---|---|---|
| 1.4.561 | 5 / 0 | |
| 1.4.560 | 5 / 0 | |
| 1.4.558 | 5 / 0 | |
| 1.4.557 | 5 / 0 | |
| 1.4.556 | 5 / 0 | |
| 1.4.555 | 5 / 0 | |
| 1.4.554 | 5 / 0 | |
| 1.4.553 | 5 / 0 | |
| 1.4.552 | 5 / 0 | |
| 1.4.551 | 5 / 0 | |
| 1.4.550 | 5 / 0 | |
| 1.4.549 | 5 / 0 | |
| 1.4.548 | 5 / 0 | |
| 1.4.547 | 5 / 0 | |
| 1.4.546 | 5 / 0 | |
| 1.4.545 | 5 / 0 | |
| 1.4.544 | 5 / 0 | |
| 1.4.542 | 5 / 0 | |
| 1.4.541 | 5 / 0 | |
| 1.4.540 | 5 / 0 | |
| 1.4.539 | 5 / 0 | |
| 1.4.538 | 5 / 0 | |
| 1.4.537 | 5 / 0 | |
| 1.4.536 | 5 / 0 | |
| 1.4.535 | 5 / 0 | |
| 1.4.534 | 5 / 0 | |
| 1.4.533 | 5 / 0 | |
| 1.4.532 | 5 / 0 | |
| 1.4.531 | 5 / 0 | |
| 1.4.530 | 5 / 0 | |
| 1.4.529 | 5 / 0 | |
| 1.4.528 | 5 / 0 | |
| 1.4.527 | 5 / 0 | |
| 1.4.526 | 5 / 0 | |
| 1.4.525 | 5 / 0 | |
| 1.4.524 | 5 / 0 | |
| 1.4.523 | 5 / 0 | |
| 1.4.522 | 5 / 0 | |
| 1.4.521 | 5 / 0 | |
| 1.4.520 | 5 / 0 | |
| 1.4.519 | 5 / 0 | |
| 1.4.518 | 5 / 0 | |
| 1.4.517 | 5 / 0 | |
| 1.4.516 | 5 / 0 | |
| 1.4.515 | 5 / 0 | |
| 1.4.514 | 5 / 0 | |
| 1.4.513 | 5 / 0 | |
| 1.4.512 | 5 / 0 | |
| 1.4.511 | 5 / 0 | |
| 1.4.510 | 5 / 0 | |
| 1.4.509 | 5 / 0 |
v1.4.561
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.560
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.558
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.557
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.556
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.555
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.554
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.553
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.552
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.551
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.550
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.