← Home

@appland/components

This repository bundles together AppMap models and Vue components in a single dependency.

3
Versions
Commons Clause + MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

kgilpindustinbyrneappland-releaselachrist

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:lucide-vue AI (phantom-deps): Component library; dependencies loaded via config/convention, not direct imports. ai
phantom-deps phantom-dep:buffer AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:mermaid AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:js-base64 AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@types/sax AI (phantom-deps): Framework-scoped package loaded by convention; stable for this package. ai
phantom-deps phantom-dep:dom-to-svg AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:highlight.js AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:sql-formatter AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:d3-flame-graph AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:marked-highlight AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:sax AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:diff AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:pako AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:events AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:vuex AI (phantom-deps): Vuex is a peer/bundled dep; phantom-dep heuristic is a stable false positive for this Vue component library. ai
phantom-deps phantom-dep:d3 AI (phantom-deps): d3 is bundled into dist; phantom-dep heuristic is a stable false positive. ai
phantom-deps phantom-dep:@appland/rpc AI (phantom-deps): Same-org dep; phantom-dep heuristic is a stable false positive. ai
phantom-deps phantom-dep:@appland/client AI (phantom-deps): Same-org dep; phantom-dep heuristic is a stable false positive. ai
phantom-deps phantom-dep:@appland/models AI (phantom-deps): Same-org dep; phantom-dep heuristic is a stable false positive. ai
phantom-deps phantom-dep:@appland/diagrams AI (phantom-deps): Same-org dep; phantom-dep heuristic is a stable false positive. ai
bogus-package bogus-package AI (bogus-package): README link dump signal is a false positive for a component library that links to its monorepo docs. ai
phantom-deps phantom-dep:vue AI (phantom-deps): Vue is a peer/bundled dep in a Vue component library; phantom-dep heuristic is a stable false positive here. ai
phantom-deps phantom-dep:@appland/sequence-diagram AI (phantom-deps): Same-org dep; phantom-dep heuristic is a stable false positive. ai

Versions (showing 3 of 3)

Version Deps Published
4.48.0 25 / 72
4.47.0 25 / 72
4.46.4 24 / 72

v4.48.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.47.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.46.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.