@telia-ace/widget-components-list-flamingo
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:list-PwyO66Gx.js | AI (source-diff): Standard Vite/Rollup minified bundle with Lit library; readable code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:index-DB9rgOBa.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:index-pDVi9hIM.js | AI (source-diff): Standard Rollup/Vite minified bundle output; readable code, no obfuscation indicators. | ai | |
| source-diff | obfuscated-file:list-L0OHXWcj.js | AI (source-diff): Standard Rollup/Vite minified bundle with Lit library; readable code and license headers present. | ai | |
| source-diff | obfuscated-file:list-D8AWpOz9.js | AI (source-diff): Minified build artifact with Google BSD license headers; standard bundler output for this package. | ai | |
| source-diff | obfuscated-file:index-A84jbWwh.js | AI (source-diff): Minified build artifact from a Lit-based widget library; no malicious patterns in sampled code. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal scoped component library with 736 versions; sparse metadata is a consistent pattern, not spam. | ai | |
| phantom-deps | phantom-dep:@telia-ace/widget-runtime-flamingo | AI (phantom-deps): Same org scope; likely a peer/runtime dep not directly imported in source. | ai | |
| provenance | no-provenance | AI (provenance): No provenance across all 736 versions; stable pattern for this internal package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across all versions of this internal package; not a malice indicator. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 1.1.139 | 3 / 0 | |
| 1.1.138 | 3 / 0 | |
| 1.1.137 | 3 / 0 | |
| 1.1.136 | 3 / 0 | |
| 1.1.135 | 3 / 0 | |
| 1.1.134 | 3 / 0 | |
| 1.1.133 | 3 / 0 | |
| 1.1.132 | 3 / 0 | |
| 1.1.131 | 3 / 0 | |
| 1.1.130 | 3 / 0 | |
| 1.1.129 | 3 / 0 | |
| 1.1.128 | 3 / 0 | |
| 1.1.127 | 3 / 0 | |
| 1.1.126 | 3 / 0 | |
| 1.1.125 | 3 / 0 | |
| 1.1.124 | 3 / 0 | |
| 1.1.123 | 3 / 0 | |
| 1.1.122 | 3 / 0 | |
| 1.1.121 | 3 / 0 | |
| 1.1.120 | 3 / 0 | |
| 1.1.119 | 3 / 0 | |
| 1.1.118 | 3 / 0 | |
| 1.1.117 | 3 / 0 | |
| 1.1.116 | 3 / 0 | |
| 1.1.77 | 3 / 0 | |
| 1.1.76 | 3 / 0 | |
| 1.1.75 | 3 / 0 | |
| 1.1.74 | 3 / 0 | |
| 1.1.73 | 3 / 0 | |
| 1.1.72 | 3 / 0 | |
| 1.1.71 | 3 / 0 | |
| 1.1.70 | 3 / 0 | |
| 1.1.69 | 3 / 0 | |
| 1.1.68 | 3 / 0 |
v1.1.77
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.76
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.75
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.74
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.73
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.72
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.71
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.70
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.69
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.68
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.