@anywidget/vue
Vue utilities for anywidget
6
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
manzt
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Small utility package; lack of Sigstore attestation is not a security risk on its own. | ai | |
| npm-metadata | suspicious-initial-version | AI (npm-metadata): Scoped @anywidget package; 0.0.0 reflects initial release of a legitimate Vue utility, not throwaway malware. | ai | |
| typosquat | typosquat.levenshtein:vite | AI (typosquat): Scoped package @anywidget/vue is a legitimate anywidget sub-package, not a typosquat of vite. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped package @anywidget/vue is a legitimate anywidget sub-package, not a typosquat of yup. | ai |