@flarehr/promoted-benefits-admin
Salpac FinOps Admin
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Runtime dep consumed via bundled output, not direct import; stable pattern for this Preact-based package. | ai | |
| phantom-deps | phantom-dep:@emotion/css | AI (phantom-deps): Emotion deps used via twin.macro/babel config; not directly imported in source. | ai | |
| phantom-deps | phantom-dep:framer-motion | AI (phantom-deps): Runtime dep bundled into dist; phantom-dep is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/cache | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/react | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@heroicons/react | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-router-dom | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai |
Versions (showing 100 of 430)
| Version | Deps | Published |
|---|---|---|
| 1.4.9462 | 12 / 26 | |
| 1.4.9223 | 12 / 26 | |
| 1.4.8963 | 12 / 26 | |
| 1.4.8808 | 12 / 26 | |
| 1.4.8535 | 12 / 26 | |
| 1.4.8371 | 12 / 26 | |
| 1.4.8150 | 12 / 26 | |
| 1.4.7870 | 12 / 26 | |
| 1.4.7667 | 12 / 26 | |
| 1.4.7471 | 12 / 26 | |
| 1.4.7397 | 12 / 26 | |
| 1.4.7319 | 12 / 26 | |
| 1.4.7121 | 12 / 26 | |
| 1.4.6957 | 12 / 26 | |
| 1.4.6731 | 12 / 26 | |
| 1.4.6548 | 12 / 26 | |
| 1.4.6438 | 12 / 26 | |
| 1.4.6334 | 12 / 26 | |
| 1.4.6247 | 12 / 26 | |
| 1.4.6097 | 12 / 26 | |
| 1.4.5882 | 12 / 26 | |
| 1.4.5649 | 12 / 26 | |
| 1.4.5408 | 12 / 26 | |
| 1.4.5212 | 12 / 26 | |
| 1.4.5136 | 12 / 26 | |
| 1.4.5058 | 12 / 26 | |
| 1.4.4814 | 12 / 26 | |
| 1.4.4632 | 12 / 26 | |
| 1.4.4484 | 12 / 26 | |
| 1.4.4265 | 12 / 26 | |
| 1.4.4053 | 12 / 26 | |
| 1.4.3978 | 12 / 26 | |
| 1.4.3922 | 12 / 26 | |
| 1.4.3753 | 12 / 26 | |
| 1.4.3547 | 12 / 26 | |
| 1.4.3330 | 12 / 26 | |
| 1.4.3087 | 12 / 26 | |
| 1.4.3010 | 12 / 26 | |
| 1.4.2952 | 12 / 26 | |
| 1.4.2881 | 12 / 26 | |
| 1.4.2801 | 12 / 26 | |
| 1.4.2624 | 12 / 26 | |
| 1.4.2456 | 12 / 26 | |
| 1.4.2293 | 12 / 26 | |
| 1.4.2229 | 12 / 26 | |
| 1.4.2202 | 12 / 26 | |
| 1.4.2140 | 12 / 26 | |
| 1.4.2063 | 12 / 26 | |
| 1.4.1994 | 12 / 26 | |
| 1.4.1843 | 12 / 26 | |
| 1.4.1689 | 12 / 26 | |
| 1.4.1542 | 12 / 26 | |
| 1.4.1466 | 12 / 26 | |
| 1.4.1454 | 12 / 26 | |
| 1.4.1446 | 12 / 26 | |
| 1.4.1262 | 12 / 26 | |
| 1.4.1138 | 12 / 26 | |
| 1.4.1074 | 12 / 26 | |
| 1.4.1050 | 12 / 26 | |
| 1.4.977 | 12 / 26 | |
| 1.4.906 | 12 / 26 | |
| 1.4.733 | 12 / 26 | |
| 1.4.526 | 12 / 26 | |
| 1.4.339 | 12 / 26 | |
| 1.4.164 | 12 / 26 | |
| 1.3.44191 | 12 / 26 | |
| 1.3.32634 | 12 / 26 | |
| 1.3.32499 | 12 / 26 | |
| 1.3.32431 | 12 / 26 | |
| 1.3.32377 | 12 / 26 | |
| 1.3.32262 | 12 / 26 | |
| 1.3.32107 | 12 / 26 | |
| 1.3.31974 | 12 / 26 | |
| 1.3.31827 | 12 / 26 | |
| 1.3.31682 | 12 / 26 | |
| 1.3.31617 | 12 / 26 | |
| 1.3.31553 | 12 / 26 | |
| 1.3.31455 | 12 / 26 | |
| 1.3.31325 | 12 / 26 | |
| 1.3.31192 | 12 / 26 | |
| 1.3.31035 | 12 / 26 | |
| 1.3.30935 | 12 / 26 | |
| 1.3.30886 | 12 / 26 | |
| 1.3.30831 | 12 / 26 | |
| 1.3.30704 | 12 / 26 | |
| 1.3.30545 | 12 / 26 | |
| 1.3.30395 | 12 / 26 | |
| 1.3.30248 | 12 / 26 | |
| 1.3.30102 | 12 / 26 | |
| 1.3.30048 | 12 / 26 | |
| 1.3.29991 | 12 / 26 | |
| 1.3.29866 | 12 / 26 | |
| 1.3.29749 | 12 / 26 | |
| 1.3.29633 | 12 / 26 | |
| 1.3.29494 | 12 / 26 | |
| 1.3.29317 | 12 / 26 | |
| 1.3.29261 | 12 / 26 | |
| 1.3.29204 | 12 / 26 | |
| 1.3.29061 | 12 / 26 | |
| 1.3.28919 | 12 / 26 |
v1.4.9462
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.9223
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.8963
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.8808
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.8535
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.8371
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.8150
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.7870
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.7667
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.7471
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.7397
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.7319
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.7121
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.6957
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.6548
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.6438
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.6334
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.6097
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.5882
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.5649
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.5136
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.5058
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.4814
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.4632
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.4484
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.4265
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.4053
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3978
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3922
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3753
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3547
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3330
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3087
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3010
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2952
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2881
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2801
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2624
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2456
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2293
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2229
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2202
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2140
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2063
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1994
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1843
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1689
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1542
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1466
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1454
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1446
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1262
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1138
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1074
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1050
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.977
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.906
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.733
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.526
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.339
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.164
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.44191
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.32634
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.32499
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.32431
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.32377
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.32262
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.32107
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.31974
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.31827
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.31682
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.31617
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.31553
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.31455
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.31325
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.31192
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.31035
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.30935
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.30886
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.30831
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.30704
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.30545
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.30395
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.30248
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.30102
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.30048
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.29991
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.29866
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.29749
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.29633
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.29494
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.29317
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.29261
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.29204
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.29061
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.28919
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.