@amsom-habitat/notif-com-ciblee
Ce package propose un composant de notification qui s'alimente a l'aide des communications ciblée d'AMSOM Habitat, la demo est visible [ici](https://www.chromatic.com/library?appId=67c180d5b0cd453429df0c9a)
1
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
amsom-habitat
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:bootstrap | AI (phantom-deps): UI library dependency; declared and used in Vue component library. | ai | |
| phantom-deps | phantom-dep:moment-timezone | AI (phantom-deps): Declared dependency; used in date utilities for Vue components. | ai | |
| phantom-deps | phantom-dep:@amsom-habitat/date-utils | AI (phantom-deps): Declared dependency; internal org package used in component library. | ai | |
| phantom-deps | phantom-dep:@fortawesome/vue-fontawesome | AI (phantom-deps): Declared dependency; standard icon library for Vue components. | ai | |
| phantom-deps | phantom-dep:@fortawesome/fontawesome-svg-core | AI (phantom-deps): Declared dependency; FontAwesome core used by icon library. | ai | |
| phantom-deps | phantom-dep:@fortawesome/free-solid-svg-icons | AI (phantom-deps): Declared dependency; FontAwesome icon set used in components. | ai | |
| phantom-deps | phantom-dep:@fortawesome/free-brands-svg-icons | AI (phantom-deps): Declared dependency; FontAwesome icon set used in components. | ai | |
| phantom-deps | phantom-dep:@fortawesome/free-regular-svg-icons | AI (phantom-deps): Declared dependency; FontAwesome icon set used in components. | ai |
Versions (showing 1 of 1)
| Version | Deps | Published |
|---|---|---|
| 0.0.6 | 8 / 18 |
v0.0.6
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.