@amsom-habitat/locataire-contrat-details
Ce package contient des composants pour gérer les détails de locataires et leurs contrats.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@amsom-habitat/bootstrap-5 | AI (phantom-deps): Same-org CSS/bootstrap dependency; likely imported via CSS rather than JS imports, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@amsom-habitat/ui | AI (phantom-deps): Same-org dep; used as peer/config dependency in Vue component library build. | ai | |
| phantom-deps | phantom-dep:@fortawesome/vue-fontawesome | AI (phantom-deps): FontAwesome Vue integration; referenced in config files, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): Likely used via config/template in bundled Vue component; phantom-dep heuristic fires on indirect usage patterns. | ai | |
| phantom-deps | phantom-dep:@fortawesome/fontawesome-svg-core | AI (phantom-deps): FontAwesome core; config-level usage, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@fortawesome/free-solid-svg-icons | AI (phantom-deps): FontAwesome icons; config-level usage, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@amsom-habitat/vertical-stepper | AI (phantom-deps): Same-org dep used as component dependency; phantom-dep heuristic is a stable false positive here. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 0.0.18 | 6 / 24 | |
| 0.0.17 | 1 / 29 | |
| 0.0.16 | 1 / 29 | |
| 0.0.15 | 1 / 29 | |
| 0.0.14 | 1 / 29 | |
| 0.0.12 | 1 / 29 | |
| 0.0.11 | 1 / 29 | |
| 0.0.10 | 1 / 29 | |
| 0.0.9 | 1 / 29 | |
| 0.0.8 | 1 / 29 | |
| 0.0.7 | 1 / 29 | |
| 0.0.6 | 1 / 29 | |
| 0.0.5 | 1 / 28 | |
| 0.0.4 | 1 / 28 | |
| 0.0.3 | 1 / 28 | |
| 0.0.2 | 7 / 21 | |
| 0.0.1 | 7 / 21 |
v0.0.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.