@xapp/contact-app
Booking & Contact Page for Form Widget
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): CI/CD publisher shift with unchanged content; consistent with automated release pipeline adoption. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Coincides with CI/CD migration, no malicious content change in this version. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Framework-scoped type package; stable false positive. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Build-time tool declared in deps; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-scripts | AI (phantom-deps): CRA build tool referenced in scripts; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/react-dom | AI (phantom-deps): Framework-scoped type package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/jest | AI (phantom-deps): Framework-scoped type package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@testing-library/react | AI (phantom-deps): Test framework package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@testing-library/jest-dom | AI (phantom-deps): Test framework package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@testing-library/user-event | AI (phantom-deps): Test framework package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@xapp/chat-widget | AI (phantom-deps): Same-org dependency; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): Framework-scoped type package; stable false positive. | ai |
Versions (showing 35 of 35)
| Version | Deps | Published |
|---|---|---|
| 1.94.7 | 14 / 8 | |
| 1.94.6 | 14 / 8 | |
| 1.94.5 | 14 / 8 | |
| 1.94.4 | 14 / 8 | |
| 1.94.3 | 14 / 8 | |
| 1.94.2 | 14 / 8 | |
| 1.94.1 | 14 / 8 | |
| 1.94.0 | 14 / 8 | |
| 1.93.0 | 14 / 8 | |
| 1.92.0 | 14 / 8 | |
| 1.91.0 | 14 / 8 | |
| 1.90.0 | 14 / 8 | |
| 1.89.1 | 14 / 8 | |
| 1.89.0 | 14 / 8 | |
| 1.88.1 | 14 / 8 | |
| 1.88.0 | 14 / 8 | |
| 1.87.2 | 14 / 8 | |
| 1.87.1 | 14 / 8 | |
| 1.87.0 | 14 / 8 | |
| 1.86.0 | 14 / 8 | |
| 1.85.1 | 14 / 8 | |
| 1.85.0 | 14 / 8 | |
| 1.84.3 | 14 / 8 | |
| 1.84.2 | 14 / 8 | |
| 1.84.1 | 14 / 8 | |
| 1.84.0 | 14 / 8 | |
| 1.83.1 | 14 / 8 | |
| 1.82.1 | 14 / 8 | |
| 1.81.5 | 14 / 8 | |
| 1.81.4 | 14 / 8 | |
| 1.81.3 | 14 / 8 | |
| 1.81.2 | 14 / 8 | |
| 1.81.1 | 14 / 8 | |
| 1.81.0 | 14 / 8 | |
| 1.80.0 | 14 / 8 |
v1.94.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.3
2 findingsThis version was published by a different npm account than previous versions on 2026-07-14. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.87.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.84.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.83.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.82.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.81.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.81.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.81.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.81.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.81.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.81.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.80.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.