@flarehr/promoted-benefits-admin
Salpac FinOps Admin
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Runtime dep consumed via bundled output, not direct import; stable pattern for this Preact-based package. | ai | |
| phantom-deps | phantom-dep:@emotion/css | AI (phantom-deps): Emotion deps used via twin.macro/babel config; not directly imported in source. | ai | |
| phantom-deps | phantom-dep:framer-motion | AI (phantom-deps): Runtime dep bundled into dist; phantom-dep is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/cache | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/react | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@heroicons/react | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-router-dom | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai |
Versions (showing 100 of 430)
| Version | Deps | Published |
|---|---|---|
| 1.4.39611 | 12 / 26 | |
| 1.4.39559 | 12 / 26 | |
| 1.4.39438 | 12 / 26 | |
| 1.4.39309 | 12 / 26 | |
| 1.4.39186 | 12 / 26 | |
| 1.4.39002 | 12 / 26 | |
| 1.4.38891 | 12 / 26 | |
| 1.4.38826 | 12 / 26 | |
| 1.4.38763 | 12 / 26 | |
| 1.4.38650 | 12 / 26 | |
| 1.4.38516 | 12 / 26 | |
| 1.4.38378 | 12 / 26 | |
| 1.4.38268 | 12 / 26 | |
| 1.4.38108 | 12 / 26 | |
| 1.4.38045 | 12 / 26 | |
| 1.4.37985 | 12 / 26 | |
| 1.4.37859 | 12 / 26 | |
| 1.4.37670 | 12 / 26 | |
| 1.4.37511 | 12 / 26 | |
| 1.4.37339 | 12 / 26 | |
| 1.4.37204 | 12 / 26 | |
| 1.4.37142 | 12 / 26 | |
| 1.4.37079 | 12 / 26 | |
| 1.4.36965 | 12 / 26 | |
| 1.4.36829 | 12 / 26 | |
| 1.4.36692 | 12 / 26 | |
| 1.4.36500 | 12 / 26 | |
| 1.4.36349 | 12 / 26 | |
| 1.4.36291 | 12 / 26 | |
| 1.4.36225 | 12 / 26 | |
| 1.4.36118 | 12 / 26 | |
| 1.4.35949 | 12 / 26 | |
| 1.4.35831 | 12 / 26 | |
| 1.4.35697 | 12 / 26 | |
| 1.4.35555 | 12 / 26 | |
| 1.4.35486 | 12 / 26 | |
| 1.4.35419 | 12 / 26 | |
| 1.4.35289 | 12 / 26 | |
| 1.4.35166 | 12 / 26 | |
| 1.4.35059 | 12 / 26 | |
| 1.4.34945 | 12 / 26 | |
| 1.4.34830 | 12 / 26 | |
| 1.4.34762 | 12 / 26 | |
| 1.4.34707 | 12 / 26 | |
| 1.4.34609 | 12 / 26 | |
| 1.4.34491 | 12 / 26 | |
| 1.4.34368 | 12 / 26 | |
| 1.4.34220 | 12 / 26 | |
| 1.4.34097 | 12 / 26 | |
| 1.4.34035 | 12 / 26 | |
| 1.4.33971 | 12 / 26 | |
| 1.4.33827 | 12 / 26 | |
| 1.4.33706 | 12 / 26 | |
| 1.4.33590 | 12 / 26 | |
| 1.4.33469 | 12 / 26 | |
| 1.4.33344 | 12 / 26 | |
| 1.4.33275 | 12 / 26 | |
| 1.4.33221 | 12 / 26 | |
| 1.4.33078 | 12 / 26 | |
| 1.4.32934 | 12 / 26 | |
| 1.4.32787 | 12 / 26 | |
| 1.4.16598 | 12 / 26 | |
| 1.4.16201 | 12 / 26 | |
| 1.4.15960 | 12 / 26 | |
| 1.4.15780 | 12 / 26 | |
| 1.4.15539 | 12 / 26 | |
| 1.4.15463 | 12 / 26 | |
| 1.4.15378 | 12 / 26 | |
| 1.4.15178 | 12 / 26 | |
| 1.4.14974 | 12 / 26 | |
| 1.4.14773 | 12 / 26 | |
| 1.4.14679 | 12 / 26 | |
| 1.4.14605 | 12 / 26 | |
| 1.4.14344 | 12 / 26 | |
| 1.4.14250 | 12 / 26 | |
| 1.4.14128 | 12 / 26 | |
| 1.4.13810 | 12 / 26 | |
| 1.4.13680 | 12 / 26 | |
| 1.4.13531 | 12 / 26 | |
| 1.4.13342 | 12 / 26 | |
| 1.4.13177 | 12 / 26 | |
| 1.4.13069 | 12 / 26 | |
| 1.4.12998 | 12 / 26 | |
| 1.4.12776 | 12 / 26 | |
| 1.4.12646 | 12 / 26 | |
| 1.4.12569 | 12 / 26 | |
| 1.4.12348 | 12 / 26 | |
| 1.4.12081 | 12 / 26 | |
| 1.4.11879 | 12 / 26 | |
| 1.4.11771 | 12 / 26 | |
| 1.4.11553 | 12 / 26 | |
| 1.4.11406 | 12 / 26 | |
| 1.4.10905 | 12 / 26 | |
| 1.4.10734 | 12 / 26 | |
| 1.4.10645 | 12 / 26 | |
| 1.4.10365 | 12 / 26 | |
| 1.4.10243 | 12 / 26 | |
| 1.4.10083 | 12 / 26 | |
| 1.4.9904 | 12 / 26 | |
| 1.4.9739 | 12 / 26 |
v1.4.39611
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.39559
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.39438
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.39309
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.39186
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.39002
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.38891
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.38826
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.38763
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.38650
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.38516
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.38378
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.38268
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.38108
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.38045
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.37985
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.37859
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.37670
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.37511
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.37339
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.37204
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.37142
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.37079
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.36965
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.36829
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.36692
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.36500
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.36349
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.36291
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.36225
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.36118
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.35949
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.35831
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.35697
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.35555
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.35486
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.35419
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.35289
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.35166
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.35059
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.34945
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.34830
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.34762
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.34707
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.34609
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.34491
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.34368
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.34220
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.34097
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.34035
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.33971
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.33827
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.33706
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.33590
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.33469
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.33344
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.33275
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.33221
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.33078
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.32934
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.32787
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.16598
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.16201
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.15960
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.15780
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.15539
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.15463
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.15378
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.15178
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.14974
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.14773
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.14679
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.14605
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.14344
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.14250
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.14128
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.13810
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.13680
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.13531
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.13342
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.13177
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.13069
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.12998
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.12776
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.12646
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.12569
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.12348
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.12081
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.11879
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.11771
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.11553
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.11406
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.10905
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.10734
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.10645
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.10365
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.10243
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.10083
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.9904
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.9739
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.