@splunk/dashboard-editors
Editors for dashboard data sources, layouts, drilldowns, tokens, and configuration
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Type-only dep; never directly imported at runtime. Stable FP for this package. | ai | |
| phantom-deps | phantom-dep:@splunk/visualization-icons | AI (phantom-deps): Same org scope; likely consumed transitively through bundled output. | ai | |
| phantom-deps | phantom-dep:@splunk/visualization-themes | AI (phantom-deps): Same org scope; likely consumed transitively through bundled output. | ai | |
| phantom-deps | phantom-dep:@splunk/visualization-context | AI (phantom-deps): Same org scope; likely consumed transitively through bundled output. | ai | |
| phantom-deps | phantom-dep:@splunk/visualizations-shared | AI (phantom-deps): Same org scope; likely consumed transitively through bundled output. | ai | |
| phantom-deps | phantom-dep:@splunk/visualization-encoding | AI (phantom-deps): Same org scope; likely consumed transitively through bundled output. | ai | |
| phantom-deps | phantom-dep:@splunk/visualization-color-palettes | AI (phantom-deps): Same org scope; likely consumed transitively through bundled output. | ai | |
| phantom-deps | phantom-dep:@splunk/dashboard-telemetry | AI (phantom-deps): Same org scope; stable FP for this bundled package. | ai | |
| dependencies | unvetted-dep:@splunk/splunk-utils | AI (dependencies): Splunk first-party sibling dep; publisher track record is clean. | ai | |
| dependencies | unvetted-dep:@splunk/react-time-range | AI (dependencies): Splunk first-party sibling dep; publisher track record is clean. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal enterprise package; sparse public metadata is expected for Splunk's private ecosystem. | ai | |
| dependencies | unvetted-dep:@splunk/time-range-utils | AI (dependencies): Splunk first-party sibling dep; publisher track record is clean. | ai | |
| phantom-deps | phantom-dep:memoize-one | AI (phantom-deps): Common false positive for bundled packages that reference deps in config only. | ai | |
| phantom-deps | phantom-dep:@splunk/time-range-utils | AI (phantom-deps): Splunk sibling dep; phantom-dep heuristic unreliable for bundled packages. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): Common false positive for bundled packages that reference deps in config only. | ai | |
| dependencies | unvetted-dep:@splunk/moment | AI (dependencies): Splunk first-party sibling dep; publisher track record is clean. | ai | |
| dependencies | unvetted-dep:@splunk/themes | AI (dependencies): Splunk first-party sibling dep; publisher track record is clean. | ai | |
| dependencies | unvetted-dep:@splunk/react-ui | AI (dependencies): Splunk first-party sibling dep; publisher track record is clean. | ai | |
| dependencies | unvetted-dep:@splunk/ui-utils | AI (dependencies): Splunk first-party sibling dep; publisher track record is clean. | ai | |
| dependencies | unvetted-dep:@splunk/react-icons | AI (dependencies): Splunk first-party sibling dep; publisher track record is clean. | ai | |
| dependencies | unvetted-dep:@splunk/dashboard-ui | AI (dependencies): Splunk first-party sibling dep; publisher track record is clean. | ai | |
| dependencies | unvetted-dep:@splunk/react-search | AI (dependencies): Splunk first-party sibling dep; publisher track record is clean. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 29.7.0 | 33 / 23 | |
| 29.6.0 | 26 / 23 | |
| 29.5.1 | 26 / 23 | |
| 29.3.0 | 26 / 30 | |
| 29.1.0 | 25 / 29 |
v29.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v29.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v29.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v29.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.