@appland/components
This repository bundles together AppMap models and Vue components in a single dependency.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:lucide-vue | AI (phantom-deps): Component library; dependencies loaded via config/convention, not direct imports. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:mermaid | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:js-base64 | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@types/sax | AI (phantom-deps): Framework-scoped package loaded by convention; stable for this package. | ai | |
| phantom-deps | phantom-dep:dom-to-svg | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:highlight.js | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:sql-formatter | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:d3-flame-graph | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:marked-highlight | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:sax | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:diff | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:pako | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:events | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Referenced in config files; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:vuex | AI (phantom-deps): Vuex is a peer/bundled dep; phantom-dep heuristic is a stable false positive for this Vue component library. | ai | |
| phantom-deps | phantom-dep:d3 | AI (phantom-deps): d3 is bundled into dist; phantom-dep heuristic is a stable false positive. | ai | |
| phantom-deps | phantom-dep:@appland/rpc | AI (phantom-deps): Same-org dep; phantom-dep heuristic is a stable false positive. | ai | |
| phantom-deps | phantom-dep:@appland/client | AI (phantom-deps): Same-org dep; phantom-dep heuristic is a stable false positive. | ai | |
| phantom-deps | phantom-dep:@appland/models | AI (phantom-deps): Same-org dep; phantom-dep heuristic is a stable false positive. | ai | |
| phantom-deps | phantom-dep:@appland/diagrams | AI (phantom-deps): Same-org dep; phantom-dep heuristic is a stable false positive. | ai | |
| bogus-package | bogus-package | AI (bogus-package): README link dump signal is a false positive for a component library that links to its monorepo docs. | ai | |
| phantom-deps | phantom-dep:vue | AI (phantom-deps): Vue is a peer/bundled dep in a Vue component library; phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:@appland/sequence-diagram | AI (phantom-deps): Same-org dep; phantom-dep heuristic is a stable false positive. | ai |
v4.48.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.47.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.46.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.