@flarehr/apollo-benefits-onboarding
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Config-referenced dep in Vite/Preact bundle; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Core framework dep referenced in build config; expected for this package. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:react-svg | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:jwt-decode | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@microsoft/clarity | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Config-referenced dep; stable pattern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Private org package; no public metadata is expected for internal packages. | ai |
Versions (showing 100 of 672)
| Version | Deps | Published |
|---|---|---|
| 0.1.3510 | 9 / 18 | |
| 0.1.3509 | 9 / 18 | |
| 0.1.3508 | 9 / 18 | |
| 0.1.3507 | 9 / 18 | |
| 0.1.3506 | 9 / 18 | |
| 0.1.3505 | 9 / 18 | |
| 0.1.3504 | 9 / 18 | |
| 0.1.3503 | 9 / 18 | |
| 0.1.3502 | 9 / 18 | |
| 0.1.3501 | 9 / 18 | |
| 0.1.3500 | 9 / 18 | |
| 0.1.3499 | 9 / 18 | |
| 0.1.3498 | 9 / 18 | |
| 0.1.3497 | 9 / 18 | |
| 0.1.3496 | 9 / 18 | |
| 0.1.3495 | 9 / 18 | |
| 0.1.3494 | 9 / 18 | |
| 0.1.3493 | 9 / 18 | |
| 0.1.3492 | 9 / 18 | |
| 0.1.3491 | 9 / 18 | |
| 0.1.3490 | 9 / 18 | |
| 0.1.3489 | 9 / 18 | |
| 0.1.3488 | 9 / 18 | |
| 0.1.3487 | 9 / 18 | |
| 0.1.3486 | 9 / 18 | |
| 0.1.3485 | 9 / 18 | |
| 0.1.3484 | 9 / 18 | |
| 0.1.3483 | 9 / 18 | |
| 0.1.3482 | 9 / 18 | |
| 0.1.3481 | 9 / 18 | |
| 0.1.3480 | 9 / 18 | |
| 0.1.3479 | 9 / 18 | |
| 0.1.3478 | 9 / 18 | |
| 0.1.3477 | 9 / 18 | |
| 0.1.3476 | 9 / 18 | |
| 0.1.3474 | 9 / 18 | |
| 0.1.3473 | 9 / 18 | |
| 0.1.3472 | 9 / 18 | |
| 0.1.3470 | 9 / 18 | |
| 0.1.3467 | 9 / 18 | |
| 0.1.3443 | 9 / 18 | |
| 0.1.3442 | 9 / 18 | |
| 0.1.3441 | 9 / 18 | |
| 0.1.3440 | 9 / 18 | |
| 0.1.3439 | 9 / 18 | |
| 0.1.3438 | 9 / 18 | |
| 0.1.3437 | 9 / 18 | |
| 0.1.3436 | 9 / 18 | |
| 0.1.3435 | 9 / 18 | |
| 0.1.3434 | 9 / 18 | |
| 0.1.3433 | 9 / 18 | |
| 0.1.3432 | 9 / 18 | |
| 0.1.3431 | 9 / 18 | |
| 0.1.3430 | 9 / 18 | |
| 0.1.3429 | 9 / 18 | |
| 0.1.3428 | 9 / 18 | |
| 0.1.3426 | 9 / 18 | |
| 0.1.3425 | 9 / 18 | |
| 0.1.3424 | 9 / 18 | |
| 0.1.3423 | 9 / 18 | |
| 0.1.3422 | 9 / 18 | |
| 0.1.3421 | 9 / 18 | |
| 0.1.3420 | 9 / 18 | |
| 0.1.3419 | 9 / 18 | |
| 0.1.3418 | 9 / 18 | |
| 0.1.3416 | 9 / 18 | |
| 0.1.3415 | 9 / 18 | |
| 0.1.3414 | 9 / 18 | |
| 0.1.3413 | 9 / 18 | |
| 0.1.3412 | 9 / 18 | |
| 0.1.3411 | 9 / 18 | |
| 0.1.3410 | 9 / 18 | |
| 0.1.3409 | 9 / 18 | |
| 0.1.3408 | 9 / 18 | |
| 0.1.3407 | 9 / 18 | |
| 0.1.3406 | 9 / 18 | |
| 0.1.3405 | 9 / 18 | |
| 0.1.3404 | 9 / 18 | |
| 0.1.3403 | 9 / 18 | |
| 0.1.3402 | 9 / 18 | |
| 0.1.3401 | 9 / 18 | |
| 0.1.3400 | 9 / 18 | |
| 0.1.3399 | 9 / 18 | |
| 0.1.3398 | 9 / 18 | |
| 0.1.3397 | 9 / 18 | |
| 0.1.3396 | 9 / 18 | |
| 0.1.3395 | 9 / 18 | |
| 0.1.3394 | 9 / 18 | |
| 0.1.3393 | 9 / 18 | |
| 0.1.3392 | 9 / 18 | |
| 0.1.3391 | 9 / 18 | |
| 0.1.3390 | 9 / 18 | |
| 0.1.3389 | 9 / 18 | |
| 0.1.3388 | 9 / 18 | |
| 0.1.3387 | 9 / 18 | |
| 0.1.3386 | 9 / 18 | |
| 0.1.3385 | 9 / 18 | |
| 0.1.3384 | 9 / 18 | |
| 0.1.3383 | 9 / 18 | |
| 0.1.3382 | 9 / 18 |
v0.1.3510
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3509
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3508
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3507
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3506
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3505
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3504
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3503
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3502
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3501
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3500
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3499
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3498
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3497
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3496
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3495
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3494
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3493
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3492
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3491
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3490
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3489
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3488
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3487
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3486
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3485
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3484
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3483
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3482
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3481
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3480
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3479
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3478
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3477
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3476
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3474
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3473
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3472
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3470
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3467
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3443
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3442
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3441
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3440
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3439
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3438
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3437
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3436
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3435
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3434
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3433
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3432
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3431
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3430
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3429
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3428
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3426
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3425
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3424
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3423
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3422
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3421
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3420
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3419
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3418
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3416
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3415
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3414
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3413
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3412
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3411
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3410
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3409
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3408
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3407
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3406
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3405
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3404
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3403
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3402
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3401
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3400
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3399
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3398
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3397
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3396
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3395
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3394
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3393
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3392
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3391
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3390
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3389
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3388
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3387
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3386
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3385
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3384
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3383
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3382
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.