@univ-lehavre/atlas-researcher-profiles
Researcher profiles service layer: REDCap/CSV ingestion, OpenAlex matching, PDF/reference extraction
16
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
pochasset
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): University monorepo package; provenance not yet configured in CI but no other risk signals present. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal university monorepo package; sparse README/keywords are cosmetic, not indicative of spam or malice. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 2.0.2 | 14 / 8 | |
| 2.0.0 | 14 / 8 | |
| 1.7.0 | 14 / 8 | |
| 1.6.7 | 13 / 8 | |
| 1.6.6 | 13 / 8 | |
| 1.6.5 | 13 / 8 | |
| 1.6.4 | 13 / 8 | |
| 1.6.3 | 13 / 8 | |
| 1.6.2 | 13 / 8 | |
| 1.6.1 | 13 / 8 | |
| 1.6.0 | 13 / 8 | |
| 1.4.1 | 11 / 8 | |
| 1.4.0 | 11 / 8 | |
| 1.3.0 | 13 / 8 | |
| 1.2.0 | 13 / 8 | |
| 1.1.0 | 13 / 8 |
v2.0.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.