← Home

@syncfusion/ej2-angular-calendars

A complete package of date or time components with built-in features such as date formatting, inline editing, multiple (range) selection, range restriction, month and year selection, strict mode, and globalization. for Angular

32
Versions
SEE LICENSE IN license
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

syncfusionorgessentialjs2syncfusion-javascript

Keywords

angularngng-calendarsej2-ng-calendars

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Syncfusion's publish pipeline change affects the whole org; no malicious signal, just missing metadata. ai
provenance publisher-changed AI (provenance): Syncfusion org account migration; syncfusion-javascript has 178 approved packages across the same scope. ai
bogus-package bogus-package AI (bogus-package): Syncfusion packages consistently have link-heavy READMEs; not a spam/phishing indicator for this org. ai
phantom-deps phantom-dep:@syncfusion/ej2-base AI (phantom-deps): Same-org transitive dep; phantom-dep heuristic is a stable false positive for this package. ai

Versions (showing 32 of 32)

Version Deps Published
34.1.29 3 / 0
33.2.15 3 / 0
33.2.13 3 / 0
33.2.12 3 / 0
33.2.10 3 / 0
33.2.8 3 / 0
33.2.7 3 / 0
33.2.6 3 / 0
33.2.5 3 / 0
33.2.4 3 / 0
33.2.3 3 / 0
33.1.44 3 / 0
32.2.9 3 / 0
32.2.8 3 / 0
32.2.7 3 / 0
32.2.6 3 / 0
32.2.5 3 / 0
32.2.4 3 / 0
32.2.3 3 / 0
32.1.25 3 / 0
32.1.24 3 / 0
32.1.23 3 / 0
32.1.22 3 / 0
32.1.21 3 / 0
32.1.20 3 / 0
32.1.19 3 / 0
31.2.18 3 / 0
31.2.16 3 / 0
31.2.15 3 / 0
31.2.12 3 / 0
31.2.10 3 / 0
31.2.5 3 / 0

v34.1.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.