@okta/okta-signin-widget
The Okta Sign-In Widget
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:handlebars | AI (dependencies): handlebars is a long-standing runtime dependency of okta-signin-widget; not a new or suspicious addition. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): oktauploader is Okta's dedicated npm publisher account; long dormancy between patch releases is normal for this enterprise widget. | ai | |
| phantom-deps | phantom-dep:fsevents | AI (phantom-deps): Optional native dep for macOS file watching; referenced in config, not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/jquery | AI (phantom-deps): Type declaration package loaded by convention; stable for this UI widget. | ai | |
| phantom-deps | phantom-dep:@types/backbone | AI (phantom-deps): Type declaration package loaded by convention; stable for this UI widget. | ai | |
| phantom-deps | phantom-dep:@types/q | AI (phantom-deps): Type declaration package; not directly imported by convention, stable for this package. | ai | |
| phantom-deps | phantom-dep:@types/selectize | AI (phantom-deps): Type declaration package loaded by convention; stable for this UI widget. | ai | |
| phantom-deps | phantom-dep:@types/underscore | AI (phantom-deps): Type declaration package loaded by convention; stable for this UI widget. | ai | |
| phantom-deps | phantom-dep:@types/eslint-scope | AI (phantom-deps): Type declaration package; nohoist-listed in workspaces config, not a runtime concern. | ai | |
| phantom-deps | phantom-dep:@types/jqueryui | AI (phantom-deps): Type declaration package loaded by convention; stable for this UI widget. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): Build/watch tool referenced in config files; not a runtime import concern. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 7.46.1 | 19 / 121 | |
| 7.46.0 | 19 / 121 | |
| 7.45.3 | 19 / 121 | |
| 7.45.2 | 19 / 121 |
v7.46.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.46.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.45.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.45.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.