@flarehr/superhero-pba-support-admin
A PBA app support admin tool which you can access from Superhero: https://test-partner.flarehr.com/superhero/#/benefits-app
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Bundled frontend package; deps referenced in config/build rather than direct imports is expected pattern. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Bundled frontend package; deps referenced in config/build rather than direct imports is expected pattern. | ai | |
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Bundled frontend package; deps referenced in config/build rather than direct imports is expected pattern. | ai | |
| phantom-deps | phantom-dep:framer-motion | AI (phantom-deps): Bundled frontend package; deps referenced in config/build rather than direct imports is expected pattern. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/forms | AI (phantom-deps): Bundled frontend package; deps referenced in config/build rather than direct imports is expected pattern. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Bundled frontend package; deps referenced in config/build rather than direct imports is expected pattern. | ai |
Versions (showing 51 of 354)
| Version | Deps | Published |
|---|---|---|
| 1.0.1230 | 6 / 23 | |
| 1.0.1229 | 6 / 23 | |
| 1.0.1228 | 6 / 23 | |
| 1.0.1227 | 6 / 23 | |
| 1.0.1226 | 6 / 23 | |
| 1.0.1225 | 6 / 23 | |
| 1.0.1224 | 6 / 23 | |
| 1.0.1223 | 6 / 23 | |
| 1.0.1222 | 6 / 23 | |
| 1.0.1221 | 6 / 23 | |
| 1.0.1220 | 6 / 23 | |
| 1.0.1219 | 6 / 23 | |
| 1.0.1218 | 6 / 23 | |
| 1.0.1217 | 6 / 23 | |
| 1.0.1216 | 6 / 23 | |
| 1.0.1215 | 6 / 23 | |
| 1.0.1214 | 6 / 23 | |
| 1.0.1213 | 6 / 23 | |
| 1.0.1212 | 6 / 23 | |
| 1.0.1211 | 6 / 23 | |
| 1.0.1210 | 6 / 23 | |
| 1.0.1209 | 6 / 23 | |
| 1.0.1208 | 6 / 23 | |
| 1.0.1207 | 6 / 23 | |
| 1.0.1206 | 6 / 23 | |
| 1.0.1205 | 6 / 23 | |
| 1.0.1204 | 6 / 23 | |
| 1.0.1203 | 6 / 23 | |
| 1.0.1202 | 6 / 23 | |
| 1.0.1201 | 6 / 23 | |
| 1.0.1200 | 6 / 23 | |
| 1.0.1199 | 6 / 23 | |
| 1.0.1198 | 6 / 23 | |
| 1.0.1197 | 6 / 23 | |
| 1.0.1196 | 6 / 23 | |
| 1.0.1195 | 6 / 23 | |
| 1.0.1194 | 6 / 23 | |
| 1.0.1193 | 6 / 23 | |
| 1.0.1192 | 6 / 23 | |
| 1.0.1191 | 6 / 23 | |
| 1.0.1190 | 6 / 23 | |
| 1.0.1189 | 6 / 23 | |
| 1.0.1188 | 6 / 23 | |
| 1.0.1187 | 6 / 23 | |
| 1.0.1186 | 6 / 23 | |
| 1.0.1185 | 6 / 23 | |
| 1.0.1184 | 6 / 23 | |
| 1.0.1183 | 6 / 23 | |
| 1.0.1182 | 6 / 23 | |
| 1.0.1181 | 6 / 23 | |
| 1.0.1180 | 6 / 23 |
v1.0.1230
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1229
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1228
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1227
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1226
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1225
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1224
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1223
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1222
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1221
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1220
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1219
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1218
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1217
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1216
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1215
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1214
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1213
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1212
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1211
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1210
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1209
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1208
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1207
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1206
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1205
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1204
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1203
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1202
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1201
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1200
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1199
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1198
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1197
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1196
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1195
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1194
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1193
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1192
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1191
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1190
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1189
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1188
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1187
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1186
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1185
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1184
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1183
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1182
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1181
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1180
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.