← Home

@swan-io/shared-business

80
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

swan-io

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Stable for this package; provenance is uncommon in npm ecosystem. ai
bogus-package bogus-package AI (bogus-package): Scoped internal library; missing repo/description/keywords typical for monorepo packages. ai
npm-metadata no-description AI (npm-metadata): Stable across 380 versions; low-risk metadata issue for established package. ai
dependencies unvetted-dep:iban AI (dependencies): Well-known IBAN validation library, long-standing ecosystem package. ai
dependencies unvetted-dep:react-atomic-state AI (dependencies): Small React state utility; no malware indicators, consistent with package purpose. ai
dependencies unvetted-dep:@placekit/client-js AI (dependencies): PlaceKit official JS client; consistent with address/business form use case. ai
dependencies unvetted-dep:@swan-io/boxed AI (dependencies): First-party swan-io dependency; same org, stable package family. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): React UI package; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:react-native-web AI (phantom-deps): Platform-specific dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Listed as runtime dep; phantom-dep heuristic false positive for this package. ai
dependencies unvetted-dep:@swan-io/request AI (dependencies): First-party swan-io dependency; same org, stable package family. ai
dependencies unvetted-dep:@swan-io/use-form AI (dependencies): First-party swan-io dependency; same org, stable package family. ai

Versions (showing 80 of 80)

Version Deps Published
15.3.1 12 / 9
15.3.0 13 / 9
15.2.0 13 / 9
15.1.2 12 / 9
15.1.1 12 / 9
15.1.0 12 / 9
15.0.0 12 / 9
14.0.0 12 / 9
13.12.0 15 / 6
13.11.3 15 / 6
13.11.2 15 / 6
13.11.1 15 / 6
13.11.0 15 / 6
13.10.2 15 / 6
13.10.1 15 / 6
13.10.0 15 / 6
13.9.3 15 / 6
13.9.2 15 / 6
13.9.1 15 / 6
13.9.0 15 / 6
13.8.0 15 / 6
13.7.14 15 / 6
13.7.13 15 / 6
13.7.12 15 / 6
13.7.11 15 / 6
13.7.10 15 / 6
13.7.9 15 / 6
13.7.8 15 / 6
13.7.7 15 / 6
13.7.6 15 / 6
13.7.5 15 / 6
13.7.4 15 / 6
13.7.3 15 / 6
13.7.2 15 / 6
13.7.1 15 / 6
13.7.0 15 / 6
13.6.7 15 / 6
13.6.6 15 / 6
13.6.5 15 / 6
13.6.4 15 / 6
13.6.3 15 / 6
13.6.2 15 / 6
13.6.1 15 / 6
13.6.0 15 / 6
13.5.3 15 / 6
13.5.2 15 / 6
13.5.1 15 / 6
13.5.0 15 / 6
13.4.15 15 / 6
13.4.14 15 / 6
13.4.13 15 / 6
13.4.12 15 / 6
13.4.11 15 / 6
13.4.10 15 / 6
13.4.9 15 / 6
13.4.8 15 / 6
13.4.7 15 / 6
13.4.2 15 / 6
13.4.1 15 / 6
13.4.0 15 / 6
13.3.0 15 / 6
13.2.5 15 / 6
13.2.4 15 / 6
13.2.3 15 / 6
13.2.2 15 / 6
13.2.1 15 / 6
13.2.0 15 / 6
13.1.10 15 / 6
13.1.9 15 / 6
13.1.8 15 / 6
13.1.7 15 / 6
13.1.6 15 / 6
13.1.4 15 / 6
13.1.3 15 / 6
13.1.2 15 / 6
13.1.1 15 / 6
13.1.0 15 / 6
13.0.2 15 / 6
13.0.1 15 / 6
13.0.0 15 / 6

v15.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.