@things-factory/operato-board
App for dashboarding
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Provenance finding confirms nalshya113 is a known prior maintainer, not a takeover. | ai | |
| dependencies | unvetted-dep:@operato/scene-material-design | AI (dependencies): Sibling scoped package within same monorepo family. | ai | |
| phantom-deps | phantom-dep:@operato/input | AI (phantom-deps): Same monorepo scoped package, config-referenced; stable FP pattern. | ai | |
| phantom-deps | phantom-dep:@things-factory/system | AI (phantom-deps): Same org scope sibling package; stable FP. | ai | |
| phantom-deps | phantom-dep:@operato/styles | AI (phantom-deps): Same monorepo scoped package, config-referenced; stable FP pattern. | ai | |
| phantom-deps | phantom-dep:@operato/utils | AI (phantom-deps): Same monorepo scoped package, config-referenced; stable FP pattern. | ai | |
| phantom-deps | phantom-dep:@things-factory/scheduler | AI (phantom-deps): Same org scope sibling package; stable FP. | ai | |
| phantom-deps | phantom-dep:@operato/scene-i18n | AI (phantom-deps): Config-referenced plugin; stable pattern for this board framework. | ai | |
| phantom-deps | phantom-dep:@things-factory/pdf | AI (phantom-deps): Same-org dependency; stable pattern for this board framework. | ai | |
| phantom-deps | phantom-dep:@operato/scene-tab | AI (phantom-deps): Config-referenced plugin; stable pattern for this board framework. | ai | |
| phantom-deps | phantom-dep:@things-factory/layout-ui | AI (phantom-deps): Same-org config-referenced dep typical of things-factory plugin architecture. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps are first-party things-factory/operato scoped packages, expected for monorepo restructure. | ai | |
| phantom-deps | phantom-dep:@operato/font | AI (phantom-deps): Config-referenced sibling package, normal for this monorepo. | ai | |
| dependencies | unvetted-dep:@operato/scene-data-transform | AI (dependencies): First-party sibling package in same ecosystem. | ai | |
| dependencies | unvetted-dep:@operato/scene-image-slider | AI (dependencies): First-party sibling package in same ecosystem. | ai | |
| dependencies | unvetted-dep:@operato/scene-google-map | AI (dependencies): First-party sibling package in same ecosystem. | ai | |
| dependencies | unvetted-dep:@operato/scene-polypath | AI (dependencies): First-party sibling package in same ecosystem. | ai | |
| dependencies | unvetted-dep:@operato/scene-gantt | AI (dependencies): First-party sibling package in same ecosystem. | ai | |
| dependencies | unvetted-dep:@operato/scene-form | AI (dependencies): First-party sibling package in same ecosystem. | ai | |
| dependencies | unvetted-dep:@operato/scene-auth | AI (dependencies): First-party sibling package in same ecosystem, not third-party unvetted code. | ai | |
| provenance | no-provenance | AI (provenance): Long-established package; provenance not historically used in this ecosystem. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP is 127.0.0.1 in a development config file — not a malicious exfiltration endpoint. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in migration index loader is a standard pattern for this framework; not arbitrary code loading. | ai |
Versions (showing 36 of 36)
| Version | Deps | Published |
|---|---|---|
| 9.2.25 | 80 / 2 | |
| 9.2.24 | 80 / 2 | |
| 9.2.13 | 80 / 2 | |
| 8.0.88 | 78 / 2 | |
| 8.0.87 | 78 / 2 | |
| 8.0.73 | 78 / 2 | |
| 8.0.64 | 78 / 2 | |
| 8.0.63 | 78 / 2 | |
| 6.4.11 | 73 / 2 | |
| 6.4.10 | 73 / 2 | |
| 4.3.822 | 62 / 2 | |
| 4.3.815 | 62 / 2 | |
| 4.3.804 | 62 / 2 | |
| 4.3.791 | 62 / 2 | |
| 4.3.790 | 62 / 2 | |
| 4.3.776 | 62 / 2 | |
| 4.3.770 | 62 / 2 | |
| 4.3.764 | 62 / 2 | |
| 4.3.740 | 62 / 2 | |
| 4.3.725 | 62 / 2 | |
| 4.3.685 | 62 / 2 | |
| 4.3.684 | 62 / 2 | |
| 4.3.677 | 62 / 2 | |
| 4.3.652 | 62 / 2 | |
| 4.3.609 | 62 / 2 | |
| 4.3.591 | 62 / 2 | |
| 4.3.582 | 62 / 2 | |
| 4.3.562 | 62 / 2 | |
| 4.3.536 | 62 / 2 | |
| 4.3.534 | 62 / 2 | |
| 4.3.533 | 62 / 2 | |
| 4.3.526 | 62 / 2 | |
| 4.3.518 | 62 / 2 | |
| 4.3.512 | 62 / 2 | |
| 4.3.511 | 62 / 2 | |
| 4.3.479 | 62 / 2 |
v9.2.24
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (horwengliang95) on 2026-05-15, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v9.2.13
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (heartyoh) than the most recent previously approved version (wengliang95) on 2026-03-19, but heartyoh is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.73
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (horwengliang95) on 2025-12-23, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.64
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (horwengliang95) on 2025-11-03, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.63
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (horwengliang95) on 2025-11-03, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.804
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wengliang95) than the most recent previously approved version (nalshya113) on 2026-04-10, but wengliang95 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.609
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.591
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.582
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.562
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.536
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.534
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.533
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.526
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.518
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.512
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.511
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.3.479
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.