@anki-eco/extensions
This library was generated with [Nx](https://nx.dev).
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:viewerjs | AI (phantom-deps): Config-referenced dep for an extensions package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@anki-eco/style-kit | AI (phantom-deps): Same-org scope dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Bundled extension package; deps declared for consumers but resolved via build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:tldraw | AI (phantom-deps): Same pattern — bundled extension with deps declared for consumers. | ai | |
| phantom-deps | phantom-dep:html2canvas | AI (phantom-deps): Same pattern — bundled extension with deps declared for consumers. | ai | |
| phantom-deps | phantom-dep:html-to-image | AI (phantom-deps): Same pattern — bundled extension with deps declared for consumers. | ai | |
| phantom-deps | phantom-dep:lucide-static | AI (phantom-deps): Same pattern — bundled extension with deps declared for consumers. | ai | |
| phantom-deps | phantom-dep:@anki-eco/shared | AI (phantom-deps): Same org scope sibling; declared for consumers, resolved via build. | ai | |
| phantom-deps | phantom-dep:image-dimensions | AI (phantom-deps): Same pattern — bundled extension with deps declared for consumers. | ai | |
| phantom-deps | phantom-dep:@anki-eco/analytics | AI (phantom-deps): Same org scope sibling; declared for consumers, resolved via build. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 1.4.1 | 13 / 4 | |
| 1.4.0 | 13 / 4 | |
| 1.3.0 | 12 / 4 | |
| 1.1.6 | 11 / 4 |
v1.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.