@flarehr/superhero-benefits-onboarding
Flare Superhero Benefits Onboarding Component
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Bundled component; deps consumed at build time and shipped in dist/, not imported directly by static analysis. | ai | |
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:jwt-decode | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@heroicons/react | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Same bundled-component pattern; stable false positive for this package. | ai |
Versions (showing 43 of 346)
| Version | Deps | Published |
|---|---|---|
| 0.2.823 | 7 / 25 | |
| 0.2.822 | 7 / 25 | |
| 0.2.821 | 7 / 25 | |
| 0.2.820 | 7 / 25 | |
| 0.2.819 | 7 / 25 | |
| 0.2.818 | 7 / 25 | |
| 0.2.817 | 7 / 25 | |
| 0.2.816 | 7 / 25 | |
| 0.2.815 | 7 / 25 | |
| 0.2.814 | 7 / 25 | |
| 0.2.813 | 7 / 25 | |
| 0.2.812 | 7 / 25 | |
| 0.2.811 | 7 / 25 | |
| 0.2.810 | 7 / 25 | |
| 0.2.809 | 7 / 25 | |
| 0.2.808 | 7 / 25 | |
| 0.2.807 | 7 / 25 | |
| 0.2.806 | 7 / 25 | |
| 0.2.805 | 7 / 25 | |
| 0.2.804 | 7 / 25 | |
| 0.2.803 | 7 / 25 | |
| 0.2.802 | 7 / 25 | |
| 0.2.801 | 7 / 25 | |
| 0.2.800 | 7 / 25 | |
| 0.2.799 | 7 / 25 | |
| 0.2.798 | 7 / 25 | |
| 0.2.797 | 7 / 25 | |
| 0.2.796 | 7 / 25 | |
| 0.2.795 | 7 / 25 | |
| 0.2.794 | 7 / 25 | |
| 0.2.793 | 7 / 25 | |
| 0.2.792 | 7 / 25 | |
| 0.2.791 | 7 / 25 | |
| 0.2.790 | 7 / 25 | |
| 0.2.789 | 7 / 25 | |
| 0.2.788 | 7 / 25 | |
| 0.2.787 | 7 / 25 | |
| 0.2.786 | 7 / 25 | |
| 0.2.785 | 7 / 25 | |
| 0.2.784 | 7 / 25 | |
| 0.2.783 | 7 / 25 | |
| 0.2.782 | 7 / 25 | |
| 0.2.781 | 7 / 25 |
v0.2.823
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.822
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.821
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.820
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.819
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.818
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.817
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.816
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.815
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.814
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.813
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.812
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.811
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.810
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.809
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.808
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.807
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.806
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.805
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.804
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.803
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.802
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.801
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.800
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.799
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.798
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.797
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.796
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.795
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.794
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.793
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.792
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.791
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.790
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.789
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.788
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.787
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.786
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.785
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.784
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.783
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.782
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.781
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.