← Home

@tap-payments/os-micro-frontend-shared

Shared components and utilities for Tap Payments micro frontends

41
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

elsharkawywaqastkalpanatapsherifashraftapsadbarkhattakmuhammadazhar007mud_fahmihaitham-tapmostafaabobakr.tapaya_tapits.sehrish.tapmahmoudallambsmsisya.safwat-tapali-sanad-tapomar_sabermadel-tap

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:build/components/ActionsDropdownMenu/ActionsDropdownMenu.js AI (source-diff): Standard vite/tsup ESM chunk barrel file; long lines are chunk import lists, not obfuscation. ai
source-diff obfuscated-file:build/components/ActionsDropdownMenu/AppMenuItem.js AI (source-diff): Same pattern — ESM re-export barrel with chunk imports; not obfuscated code. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): Bundled library; dompurify is used inside build chunks, not directly imported at source level. ai
provenance no-provenance AI (provenance): Internal org package with high version count; provenance absence is consistent across all versions and not a risk signal here. ai
phantom-deps phantom-dep:@hookform/resolvers AI (phantom-deps): Same pattern; stable false positive for this shared library package. ai
phantom-deps phantom-dep:@uiw/react-json-view AI (phantom-deps): Same pattern; stable false positive for this shared library package. ai
phantom-deps phantom-dep:dayjs AI (phantom-deps): Shared component library; deps referenced in config/re-exports, not direct imports. ai
phantom-deps phantom-dep:react-window-infinite-loader AI (phantom-deps): Same pattern; stable false positive for this shared library package. ai
phantom-deps phantom-dep:react-virtualized-auto-sizer AI (phantom-deps): Same pattern; stable false positive for this shared library package. ai
phantom-deps phantom-dep:recharts AI (phantom-deps): Same pattern; stable false positive for this shared library package. ai
phantom-deps phantom-dep:react-draggable AI (phantom-deps): Same pattern; stable false positive for this shared library package. ai
phantom-deps phantom-dep:react-router-dom AI (phantom-deps): Listed as peerDependency and dependency; phantom-dep is a false positive here. ai

Versions (showing 41 of 41)

Version Deps Published
0.3.69 24 / 41
0.3.68 24 / 41
0.3.67 24 / 41
0.3.66 24 / 41
0.3.65 24 / 41
0.3.64 24 / 41
0.3.63 24 / 41
0.3.62 24 / 41
0.3.61 24 / 41
0.3.60 24 / 41
0.3.59 24 / 39
0.3.58 24 / 39
0.3.57 24 / 39
0.3.56 24 / 39
0.3.55 24 / 38
0.3.54 24 / 38
0.3.53 24 / 38
0.3.52 24 / 38
0.3.51 24 / 38
0.3.50 24 / 38
0.3.49 24 / 38
0.3.48 24 / 38
0.3.47 24 / 38
0.3.46 24 / 38
0.3.45 24 / 38
0.3.44 24 / 38
0.3.43 24 / 38
0.3.42 24 / 38
0.3.41 24 / 38
0.3.40 24 / 38
0.3.39 24 / 38
0.3.38 24 / 38
0.3.37 24 / 38
0.2.34 24 / 37
0.2.9 24 / 37
0.1.552 23 / 37
0.1.494 23 / 37
0.1.492 23 / 37
0.1.483 23 / 37
0.1.480 23 / 37
0.1.479 23 / 37

v0.3.69

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.68

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.67

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.66

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.65

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.64

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.63

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.62

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.61

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.60

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.59

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.58

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.57

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.56

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.55

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.54

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.53

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.52

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.51

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.50

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.49

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.48

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.47

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.46

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.45

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.44

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.43

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.42

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.41

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.40

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.39

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.38

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.37

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.