@telia-ace/widget-components-list-flamingo
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:list-PwyO66Gx.js | AI (source-diff): Standard Vite/Rollup minified bundle with Lit library; readable code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:index-DB9rgOBa.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:index-pDVi9hIM.js | AI (source-diff): Standard Rollup/Vite minified bundle output; readable code, no obfuscation indicators. | ai | |
| source-diff | obfuscated-file:list-L0OHXWcj.js | AI (source-diff): Standard Rollup/Vite minified bundle with Lit library; readable code and license headers present. | ai | |
| source-diff | obfuscated-file:list-D8AWpOz9.js | AI (source-diff): Minified build artifact with Google BSD license headers; standard bundler output for this package. | ai | |
| source-diff | obfuscated-file:index-A84jbWwh.js | AI (source-diff): Minified build artifact from a Lit-based widget library; no malicious patterns in sampled code. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal scoped component library with 736 versions; sparse metadata is a consistent pattern, not spam. | ai | |
| phantom-deps | phantom-dep:@telia-ace/widget-runtime-flamingo | AI (phantom-deps): Same org scope; likely a peer/runtime dep not directly imported in source. | ai | |
| provenance | no-provenance | AI (provenance): No provenance across all 736 versions; stable pattern for this internal package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across all versions of this internal package; not a malice indicator. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 1.1.138 | 3 / 0 | |
| 1.1.137 | 3 / 0 | |
| 1.1.136 | 3 / 0 | |
| 1.1.135 | 3 / 0 | |
| 1.1.134 | 3 / 0 | |
| 1.1.133 | 3 / 0 | |
| 1.1.132 | 3 / 0 | |
| 1.1.131 | 3 / 0 | |
| 1.1.130 | 3 / 0 | |
| 1.1.129 | 3 / 0 | |
| 1.1.128 | 3 / 0 | |
| 1.1.127 | 3 / 0 | |
| 1.1.126 | 3 / 0 | |
| 1.1.125 | 3 / 0 | |
| 1.1.124 | 3 / 0 | |
| 1.1.123 | 3 / 0 | |
| 1.1.122 | 3 / 0 | |
| 1.1.121 | 3 / 0 | |
| 1.1.120 | 3 / 0 | |
| 1.1.119 | 3 / 0 | |
| 1.1.118 | 3 / 0 | |
| 1.1.117 | 3 / 0 | |
| 1.1.116 | 3 / 0 |
v1.1.138
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.137
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.136
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.135
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2026-03-20, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.134
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2026-03-16, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.133
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2026-03-13, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.132
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2026-03-13, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.131
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2026-03-10, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.130
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2026-02-18, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.129
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2026-01-27, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.128
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2026-01-13, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.127
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2026-01-08, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.126
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2025-12-18, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.125
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2025-12-16, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.124
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2025-12-16, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.123
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2025-12-16, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.122
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andreas.boukaras) than the most recent previously approved version (donami) on 2025-08-18, but andreas.boukaras is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.121
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.120
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.119
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.118
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.117
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.116
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.