@flarehr/apollo-benefits-onboarding
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Config-referenced dep in Vite/Preact bundle; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Core framework dep referenced in build config; expected for this package. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:react-svg | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:jwt-decode | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@microsoft/clarity | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Private org package; no public metadata is expected for internal packages. | ai |
Versions (showing 100 of 673)
| Version | Deps | Published |
|---|---|---|
| 0.1.3173 | 9 / 18 | |
| 0.1.3171 | 9 / 18 | |
| 0.1.3169 | 9 / 18 | |
| 0.1.3168 | 9 / 18 | |
| 0.1.3167 | 9 / 18 | |
| 0.1.3166 | 9 / 18 | |
| 0.1.3165 | 9 / 18 | |
| 0.1.3164 | 9 / 18 | |
| 0.1.3163 | 9 / 18 | |
| 0.1.3162 | 9 / 18 | |
| 0.1.3161 | 9 / 18 | |
| 0.1.3160 | 9 / 18 | |
| 0.1.3159 | 9 / 18 | |
| 0.1.3157 | 9 / 18 | |
| 0.1.3156 | 9 / 18 | |
| 0.1.3155 | 9 / 18 | |
| 0.1.3154 | 9 / 18 | |
| 0.1.3152 | 9 / 18 | |
| 0.1.3149 | 9 / 18 | |
| 0.1.3148 | 9 / 18 | |
| 0.1.3147 | 9 / 18 | |
| 0.1.3146 | 9 / 18 | |
| 0.1.3145 | 9 / 18 | |
| 0.1.3144 | 9 / 18 | |
| 0.1.3143 | 9 / 18 | |
| 0.1.3142 | 9 / 18 | |
| 0.1.3141 | 9 / 18 | |
| 0.1.3140 | 9 / 18 | |
| 0.1.3139 | 9 / 18 | |
| 0.1.3138 | 9 / 18 | |
| 0.1.3137 | 9 / 18 | |
| 0.1.3136 | 9 / 18 | |
| 0.1.3134 | 9 / 18 | |
| 0.1.3133 | 9 / 18 | |
| 0.1.3132 | 9 / 18 | |
| 0.1.3131 | 9 / 18 | |
| 0.1.3130 | 9 / 18 | |
| 0.1.3129 | 9 / 18 | |
| 0.1.3128 | 9 / 18 | |
| 0.1.3127 | 9 / 18 | |
| 0.1.3126 | 9 / 18 | |
| 0.1.3124 | 9 / 18 | |
| 0.1.3123 | 9 / 18 | |
| 0.1.3121 | 9 / 18 | |
| 0.1.3098 | 9 / 18 | |
| 0.1.3097 | 9 / 18 | |
| 0.1.3096 | 9 / 18 | |
| 0.1.3095 | 9 / 18 | |
| 0.1.3094 | 9 / 18 | |
| 0.1.3093 | 9 / 18 | |
| 0.1.3092 | 9 / 18 | |
| 0.1.3091 | 9 / 18 | |
| 0.1.3090 | 9 / 18 | |
| 0.1.3089 | 9 / 18 | |
| 0.1.3088 | 9 / 18 | |
| 0.1.3087 | 9 / 18 | |
| 0.1.3086 | 9 / 18 | |
| 0.1.3085 | 9 / 18 | |
| 0.1.3084 | 9 / 18 | |
| 0.1.3083 | 9 / 18 | |
| 0.1.3082 | 9 / 18 | |
| 0.1.3081 | 9 / 18 | |
| 0.1.3080 | 9 / 18 | |
| 0.1.3079 | 9 / 18 | |
| 0.1.3078 | 9 / 18 | |
| 0.1.3077 | 9 / 18 | |
| 0.1.3076 | 9 / 18 | |
| 0.1.3075 | 9 / 18 | |
| 0.1.3074 | 9 / 18 | |
| 0.1.3073 | 9 / 18 | |
| 0.1.3072 | 9 / 18 | |
| 0.1.3071 | 9 / 18 | |
| 0.1.3070 | 9 / 18 | |
| 0.1.3069 | 9 / 18 | |
| 0.1.3068 | 9 / 18 | |
| 0.1.3067 | 9 / 18 | |
| 0.1.3066 | 9 / 18 | |
| 0.1.3065 | 9 / 18 | |
| 0.1.3064 | 9 / 18 | |
| 0.1.3063 | 9 / 18 | |
| 0.1.3062 | 9 / 18 | |
| 0.1.3061 | 9 / 18 | |
| 0.1.3060 | 9 / 18 | |
| 0.1.3059 | 9 / 18 | |
| 0.1.3058 | 9 / 18 | |
| 0.1.3057 | 9 / 18 | |
| 0.1.3056 | 9 / 18 | |
| 0.1.3055 | 9 / 18 | |
| 0.1.3054 | 9 / 18 | |
| 0.1.3053 | 9 / 18 | |
| 0.1.3052 | 9 / 18 | |
| 0.1.3051 | 9 / 18 | |
| 0.1.3050 | 9 / 18 | |
| 0.1.3049 | 9 / 18 | |
| 0.1.3048 | 9 / 18 | |
| 0.1.3047 | 9 / 18 | |
| 0.1.3046 | 9 / 18 | |
| 0.1.3045 | 9 / 18 | |
| 0.1.3044 | 9 / 18 | |
| 0.1.3043 | 9 / 18 |
v0.1.3173
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3171
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3169
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3168
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3167
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3166
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3165
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3164
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3163
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3162
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3161
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3160
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3159
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3157
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3156
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3155
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3154
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3152
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3149
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3148
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3147
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3146
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3145
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3144
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3143
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3142
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3141
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3140
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3139
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3138
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3137
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3136
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3134
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3133
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3132
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3131
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3130
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3129
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3128
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3127
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3126
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3124
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3123
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3121
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3098
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3097
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3096
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3095
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3094
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3093
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3092
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3091
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3090
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3089
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3088
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3087
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3086
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3085
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3084
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3083
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3082
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3081
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3080
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3079
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3078
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3077
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3076
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3075
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3074
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3073
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3072
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3071
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3070
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3069
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3068
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3067
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3066
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3065
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3064
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3063
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3062
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3061
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3060
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3059
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3058
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3057
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3056
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3055
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3054
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3053
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3052
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3051
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3050
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3049
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3048
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3047
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3046
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3045
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3044
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3043
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.