@rh-support/manage
Customer Support Manage App
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Active org-internal package; maintainer additions are routine team changes within Red Hat's support tooling org. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Peer dep referenced in config; standard React library pattern. | ai | |
| phantom-deps | phantom-dep:@rh-support/configs | AI (phantom-deps): Same org scope; used via config convention, not direct import. | ai | |
| phantom-deps | phantom-dep:i18next | AI (phantom-deps): Config-file reference pattern expected for this React component library. | ai | |
| phantom-deps | phantom-dep:@patternfly/react-table | AI (phantom-deps): Config-file reference; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/react-beautiful-dnd | AI (phantom-deps): Type-only package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@patternfly/patternfly | AI (phantom-deps): Config-file reference; stable false positive for this package. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 2.6.1 | 19 / 16 | |
| 2.5.192 | 19 / 16 | |
| 2.5.185 | 19 / 16 | |
| 2.5.171 | 19 / 16 | |
| 2.5.170 | 19 / 16 | |
| 2.5.162 | 19 / 16 | |
| 2.5.129 | 19 / 16 | |
| 2.5.121 | 19 / 16 | |
| 2.5.108 | 19 / 16 | |
| 2.5.103 | 19 / 16 | |
| 2.5.97 | 19 / 16 | |
| 2.5.85 | 19 / 16 | |
| 2.5.84 | 19 / 16 | |
| 2.5.79 | 19 / 16 | |
| 2.5.78 | 19 / 16 | |
| 2.5.76 | 19 / 16 | |
| 2.5.71 | 19 / 16 | |
| 2.5.70 | 19 / 16 | |
| 2.5.62 | 19 / 16 | |
| 2.5.58 | 19 / 16 | |
| 2.5.37 | 19 / 16 | |
| 2.5.31 | 19 / 16 | |
| 2.5.29 | 19 / 16 | |
| 2.5.28 | 19 / 16 | |
| 2.5.26 | 19 / 16 | |
| 2.5.25 | 19 / 16 | |
| 2.5.24 | 19 / 16 |
v2.6.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.192
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bkale) than the most recent previously approved version (arajak) on 2026-06-04, but bkale is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.5.185
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.171
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.170
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.162
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.129
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.121
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.108
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.103
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.97
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.85
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.84
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.79
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.78
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.76
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.71
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.70
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.62
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.58
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.