← Home

@verii/components-organizations-registrar

This package contains the main components for creating a registry of organizations. The project is written in pure JS.

14
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

lfdt-npmhyperledger-ghci

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata no-description AI (npm-metadata): Component library with clear exports and purpose; missing description is metadata gap, not security concern. ai
phantom-deps phantom-dep:@auth0/auth0-react AI (phantom-deps): Dependency is properly declared and used in configuration; phantom-dep pattern is normal for component libraries with indirect dependency usage. ai
phantom-deps phantom-dep:ra-data-local-storage AI (phantom-deps): Dependency is properly declared and used in configuration; phantom-dep pattern is normal for component libraries with indirect dependency usage. ai
bogus-package bogus-package AI (bogus-package): Scoped package with well-structured exports and proper metadata; minimal README is acceptable for monorepo component libraries. ai
dependencies unvetted-dep:autosuggest-highlight AI (dependencies): Small, stable utility library for text highlighting; no security concerns. ai
dependencies unvetted-dep:ra-core AI (dependencies): ra-core is a well-known React Admin framework core package; unvetted status reflects review queue lag, not actual risk. ai
dependencies unvetted-dep:ra-data-local-storage AI (dependencies): Part of the react-admin ecosystem; legitimate data provider for local storage; no security concerns. ai
dependencies unvetted-dep:react-admin AI (dependencies): react-admin is a widely-used, legitimate open-source admin framework; no security concerns. ai
dependencies unvetted-dep:@auth0/auth0-react AI (dependencies): Official Auth0 React SDK from a major identity provider; well-maintained and widely trusted. ai
dependencies unvetted-dep:@react-pdf/renderer AI (dependencies): Established React PDF rendering library with broad ecosystem adoption; no security concerns. ai

Versions (showing 14 of 14)

Version Deps Published
1.1.3 14 / 28
1.1.2 14 / 28
1.1.1 14 / 28
1.1.0 14 / 28
1.0.9 12 / 28
1.0.8 12 / 28
1.0.7 12 / 28
1.0.6 12 / 28
1.0.5 12 / 28
1.0.4 12 / 28
1.0.3 12 / 28
1.0.2 12 / 28
1.0.1 12 / 28
1.0.0 12 / 28

v1.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.