@flarehr/promoted-benefits-admin
Salpac FinOps Admin
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Runtime dep consumed via bundled output, not direct import; stable pattern for this Preact-based package. | ai | |
| phantom-deps | phantom-dep:@emotion/css | AI (phantom-deps): Emotion deps used via twin.macro/babel config; not directly imported in source. | ai | |
| phantom-deps | phantom-dep:framer-motion | AI (phantom-deps): Runtime dep bundled into dist; phantom-dep is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/cache | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/react | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@heroicons/react | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-router-dom | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai |
Versions (showing 100 of 429)
| Version | Deps | Published |
|---|---|---|
| 1.4.52612 | 12 / 26 | |
| 1.4.52444 | 12 / 26 | |
| 1.4.52296 | 12 / 26 | |
| 1.4.52133 | 12 / 26 | |
| 1.4.52048 | 12 / 26 | |
| 1.4.51994 | 12 / 26 | |
| 1.4.51846 | 12 / 26 | |
| 1.4.51693 | 12 / 26 | |
| 1.4.51535 | 12 / 26 | |
| 1.4.51383 | 12 / 26 | |
| 1.4.51225 | 12 / 26 | |
| 1.4.51149 | 12 / 26 | |
| 1.4.51078 | 12 / 26 | |
| 1.4.50940 | 12 / 26 | |
| 1.4.50743 | 12 / 26 | |
| 1.4.50584 | 12 / 26 | |
| 1.4.50419 | 12 / 26 | |
| 1.4.50262 | 12 / 26 | |
| 1.4.50183 | 12 / 26 | |
| 1.4.50112 | 12 / 26 | |
| 1.4.49985 | 12 / 26 | |
| 1.4.49814 | 12 / 26 | |
| 1.4.49645 | 12 / 26 | |
| 1.4.49333 | 12 / 26 | |
| 1.4.49266 | 12 / 26 | |
| 1.4.49200 | 12 / 26 | |
| 1.4.49041 | 12 / 26 | |
| 1.4.48911 | 12 / 26 | |
| 1.4.48738 | 12 / 26 | |
| 1.4.48577 | 12 / 26 | |
| 1.4.48411 | 12 / 26 | |
| 1.4.48352 | 12 / 26 | |
| 1.4.48271 | 12 / 26 | |
| 1.4.48158 | 12 / 26 | |
| 1.4.48010 | 12 / 26 | |
| 1.4.47869 | 12 / 26 | |
| 1.4.47677 | 12 / 26 | |
| 1.4.47524 | 12 / 26 | |
| 1.4.47459 | 12 / 26 | |
| 1.4.47392 | 12 / 26 | |
| 1.4.47261 | 12 / 26 | |
| 1.4.47151 | 12 / 26 | |
| 1.4.46941 | 12 / 26 | |
| 1.4.46783 | 12 / 26 | |
| 1.4.46655 | 12 / 26 | |
| 1.4.46594 | 12 / 26 | |
| 1.4.46524 | 12 / 26 | |
| 1.4.46385 | 12 / 26 | |
| 1.4.46272 | 12 / 26 | |
| 1.4.46157 | 12 / 26 | |
| 1.4.45987 | 12 / 26 | |
| 1.4.45868 | 12 / 26 | |
| 1.4.45793 | 12 / 26 | |
| 1.4.45729 | 12 / 26 | |
| 1.4.45606 | 12 / 26 | |
| 1.4.45464 | 12 / 26 | |
| 1.4.45311 | 12 / 26 | |
| 1.4.44834 | 12 / 26 | |
| 1.4.44767 | 12 / 26 | |
| 1.4.44715 | 12 / 26 | |
| 1.4.44585 | 12 / 26 | |
| 1.4.44413 | 12 / 26 | |
| 1.4.44268 | 12 / 26 | |
| 1.4.44113 | 12 / 26 | |
| 1.4.43960 | 12 / 26 | |
| 1.4.43894 | 12 / 26 | |
| 1.4.43843 | 12 / 26 | |
| 1.4.43706 | 12 / 26 | |
| 1.4.43563 | 12 / 26 | |
| 1.4.43432 | 12 / 26 | |
| 1.4.43261 | 12 / 26 | |
| 1.4.43112 | 12 / 26 | |
| 1.4.43047 | 12 / 26 | |
| 1.4.42983 | 12 / 26 | |
| 1.4.42828 | 12 / 26 | |
| 1.4.42667 | 12 / 26 | |
| 1.4.42541 | 12 / 26 | |
| 1.4.42393 | 12 / 26 | |
| 1.4.42230 | 12 / 26 | |
| 1.4.42171 | 12 / 26 | |
| 1.4.42098 | 12 / 26 | |
| 1.4.41981 | 12 / 26 | |
| 1.4.41813 | 12 / 26 | |
| 1.4.41673 | 12 / 26 | |
| 1.4.41528 | 12 / 26 | |
| 1.4.41341 | 12 / 26 | |
| 1.4.41270 | 12 / 26 | |
| 1.4.41217 | 12 / 26 | |
| 1.4.41080 | 12 / 26 | |
| 1.4.40967 | 12 / 26 | |
| 1.4.40822 | 12 / 26 | |
| 1.4.40704 | 12 / 26 | |
| 1.4.40571 | 12 / 26 | |
| 1.4.40503 | 12 / 26 | |
| 1.4.40441 | 12 / 26 | |
| 1.4.40301 | 12 / 26 | |
| 1.4.40145 | 12 / 26 | |
| 1.4.39986 | 12 / 26 | |
| 1.4.39808 | 12 / 26 | |
| 1.4.39684 | 12 / 26 |
v1.4.52612
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.52444
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.52296
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.52133
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.52048
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.51994
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.51846
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.51693
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.51535
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.51383
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.51225
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.51149
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.51078
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.50940
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.50743
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.50584
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.50419
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.50262
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.50183
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.50112
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.49985
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.49814
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.49645
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.49333
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.49266
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.49200
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.49041
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.48911
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.48738
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.48577
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.48411
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.48352
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.48271
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.48158
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.48010
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.47869
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.47677
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.47524
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.47459
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.47392
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.47261
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.47151
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.46941
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.46783
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.46655
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.46594
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.46524
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.46385
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.46272
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.46157
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.45987
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.45868
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.45793
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.45729
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.45606
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.45464
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.45311
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.44834
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.44767
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.44715
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.44585
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.44413
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.44268
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.44113
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.43960
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.43894
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.43843
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.43706
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.43563
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.43432
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.43261
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.43112
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.43047
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.42983
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.42828
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.42667
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.42541
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.42393
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.42230
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.42171
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.42098
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.41981
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.41813
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.41673
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.41528
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.41341
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.41270
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.41217
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.41080
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.40967
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.40822
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.40704
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.40571
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.40503
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.40441
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.40301
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.40145
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.39986
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.39808
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.39684
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.