@shipengine/giger
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/lodash | AI (phantom-deps): TypeScript type package; conventionally loaded by TS compiler, not direct import. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Babel runtime helper; injected by @babel/plugin-transform-runtime, not direct import. | ai | |
| phantom-deps | phantom-dep:@types/react-modal | AI (phantom-deps): TypeScript type package; conventionally loaded by TS compiler, not direct import. | ai | |
| phantom-deps | phantom-dep:@types/react-datepicker | AI (phantom-deps): TypeScript type package; conventionally loaded by TS compiler, not direct import. | ai |
Versions (showing 26 of 26)
| Version | Deps | Published |
|---|---|---|
| 1.28.3 | 19 / 5 | |
| 1.28.2 | 19 / 5 | |
| 1.28.1 | 19 / 5 | |
| 1.28.0 | 19 / 5 | |
| 1.27.3 | 19 / 5 | |
| 1.27.2 | 19 / 5 | |
| 1.27.1 | 19 / 5 | |
| 1.27.0 | 19 / 5 | |
| 1.26.2 | 19 / 5 | |
| 1.26.1 | 19 / 5 | |
| 1.26.0 | 19 / 5 | |
| 1.23.1 | 19 / 5 | |
| 1.23.0 | 19 / 5 | |
| 1.22.2 | 19 / 5 | |
| 1.22.1 | 19 / 5 | |
| 1.22.0 | 19 / 5 | |
| 1.21.0 | 19 / 5 | |
| 1.20.25 | 19 / 5 | |
| 1.20.24 | 19 / 5 | |
| 1.20.23 | 19 / 5 | |
| 1.20.22 | 19 / 5 | |
| 1.20.21 | 19 / 5 | |
| 1.20.20 | 19 / 5 | |
| 1.20.19 | 19 / 5 | |
| 1.20.18 | 19 / 5 | |
| 1.20.17 | 19 / 5 |
v1.28.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.28.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.28.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.27.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.27.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.27.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.26.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.26.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.26.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.23.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.22.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.22.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.20.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.20.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.