@verii/components-organizations-registrar
This package contains the main components for creating a registry of organizations. The project is written in pure JS.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Component library with clear exports and purpose; missing description is metadata gap, not security concern. | ai | |
| phantom-deps | phantom-dep:@auth0/auth0-react | AI (phantom-deps): Dependency is properly declared and used in configuration; phantom-dep pattern is normal for component libraries with indirect dependency usage. | ai | |
| phantom-deps | phantom-dep:ra-data-local-storage | AI (phantom-deps): Dependency is properly declared and used in configuration; phantom-dep pattern is normal for component libraries with indirect dependency usage. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped package with well-structured exports and proper metadata; minimal README is acceptable for monorepo component libraries. | ai | |
| dependencies | unvetted-dep:autosuggest-highlight | AI (dependencies): Small, stable utility library for text highlighting; no security concerns. | ai | |
| dependencies | unvetted-dep:ra-core | AI (dependencies): ra-core is a well-known React Admin framework core package; unvetted status reflects review queue lag, not actual risk. | ai | |
| dependencies | unvetted-dep:ra-data-local-storage | AI (dependencies): Part of the react-admin ecosystem; legitimate data provider for local storage; no security concerns. | ai | |
| dependencies | unvetted-dep:react-admin | AI (dependencies): react-admin is a widely-used, legitimate open-source admin framework; no security concerns. | ai | |
| dependencies | unvetted-dep:@auth0/auth0-react | AI (dependencies): Official Auth0 React SDK from a major identity provider; well-maintained and widely trusted. | ai | |
| dependencies | unvetted-dep:@react-pdf/renderer | AI (dependencies): Established React PDF rendering library with broad ecosystem adoption; no security concerns. | ai |
Versions (showing 14 of 14)
| Version | Deps | Published |
|---|---|---|
| 1.1.3 | 14 / 28 | |
| 1.1.2 | 14 / 28 | |
| 1.1.1 | 14 / 28 | |
| 1.1.0 | 14 / 28 | |
| 1.0.9 | 12 / 28 | |
| 1.0.8 | 12 / 28 | |
| 1.0.7 | 12 / 28 | |
| 1.0.6 | 12 / 28 | |
| 1.0.5 | 12 / 28 | |
| 1.0.4 | 12 / 28 | |
| 1.0.3 | 12 / 28 | |
| 1.0.2 | 12 / 28 | |
| 1.0.1 | 12 / 28 | |
| 1.0.0 | 12 / 28 |
v1.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.