@socialgouv/kali-data
[![License][img-license]][link-license] [![NPM Version][img-npm]][link-npm] [![Code Coverage][img-coverage]][link-coverage]
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:node-xlsx | AI (phantom-deps): Used in build/data scripts (fetch, match, list), not imported in src; stable false positive for this data package. | ai | |
| phantom-deps | phantom-dep:csv-parser | AI (phantom-deps): Used in build/data scripts, not in src imports; stable false positive for this data package. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads local JSON data files by agreementId from a known local path; not arbitrary module loading. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 3.484.0 | 5 / 24 | |
| 3.483.0 | 5 / 24 | |
| 3.481.0 | 5 / 24 | |
| 3.480.0 | 5 / 24 | |
| 3.479.0 | 5 / 24 | |
| 3.478.0 | 5 / 24 | |
| 3.477.0 | 5 / 24 | |
| 3.476.0 | 5 / 24 | |
| 3.475.0 | 5 / 24 | |
| 3.474.1 | 5 / 24 | |
| 3.474.0 | 5 / 24 | |
| 3.473.0 | 5 / 24 | |
| 3.472.0 | 5 / 24 | |
| 3.470.0 | 5 / 24 | |
| 3.469.0 | 5 / 24 | |
| 3.468.0 | 5 / 24 | |
| 3.467.0 | 5 / 24 | |
| 3.466.0 | 5 / 24 | |
| 3.465.0 | 5 / 24 | |
| 3.464.0 | 5 / 24 | |
| 3.462.0 | 5 / 24 | |
| 3.461.0 | 5 / 24 | |
| 3.459.0 | 5 / 24 | |
| 3.458.0 | 5 / 24 | |
| 3.456.0 | 5 / 24 | |
| 3.455.0 | 5 / 24 | |
| 3.454.0 | 5 / 24 | |
| 3.452.0 | 5 / 24 | |
| 3.450.0 | 5 / 24 | |
| 3.449.0 | 5 / 24 | |
| 3.448.0 | 5 / 24 | |
| 3.445.0 | 5 / 24 | |
| 3.443.0 | 5 / 24 | |
| 3.440.0 | 5 / 24 |
v3.484.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.483.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.481.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.480.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.479.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.478.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.477.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.476.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.475.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.474.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.474.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.473.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.472.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.470.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.469.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.468.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.467.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.466.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.465.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.464.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.462.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.461.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.459.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.458.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.456.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.455.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.454.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.