@arbocollab/arbo-plugin-item-table
<p align="center"> <strong>A powerful and reusable Vue 3 component for displaying and managing item data in a feature-rich, infinite-scrolling table.</strong> </p>
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:item-table | AI (dependencies): Internal monorepo workspace:* dep; not an external package risk. | ai | |
| dependencies | unvetted-dep:api-services | AI (dependencies): Internal monorepo workspace:* dep; not an external package risk. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): High-velocity monorepo with 325 versions; rapid CI publishes are expected for this package. | ai | |
| phantom-deps | phantom-dep:item-table | AI (phantom-deps): Monorepo workspace:* sibling package; phantom-dep is a false positive here. | ai | |
| phantom-deps | phantom-dep:api-services | AI (phantom-deps): Monorepo workspace:* sibling package; phantom-dep is a false positive here. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Peer dependency pattern; referenced in config files only. | ai | |
| phantom-deps | phantom-dep:dexie | AI (phantom-deps): Peer dependency pattern; referenced in config files only. | ai | |
| phantom-deps | phantom-dep:luxon | AI (phantom-deps): Peer dependency pattern; referenced in config files only. | ai | |
| phantom-deps | phantom-dep:pinia | AI (phantom-deps): Peer dependency pattern; referenced in config files only. | ai | |
| phantom-deps | phantom-dep:tippy.js | AI (phantom-deps): Peer dependency pattern; referenced in config files only. | ai | |
| phantom-deps | phantom-dep:vue-i18n | AI (phantom-deps): Peer dependency pattern; referenced in config files only. | ai | |
| dependencies | unvetted-dep:@arbocollab/item-table | AI (dependencies): workspace:* monorepo sibling; not an external dependency. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): Peer dependency pattern; referenced in config files only. | ai | |
| phantom-deps | phantom-dep:@popperjs/core | AI (phantom-deps): Peer dependency pattern; referenced in config files only. | ai | |
| phantom-deps | phantom-dep:@arbocollab/item-table | AI (phantom-deps): workspace:* monorepo sibling; phantom-dep is expected. | ai | |
| phantom-deps | phantom-dep:@arbocollab/vue-ag-grid | AI (phantom-deps): workspace:* monorepo sibling; phantom-dep is expected. | ai | |
| phantom-deps | phantom-dep:@arbocollab/api-services | AI (phantom-deps): workspace:* monorepo sibling; phantom-dep is expected. | ai | |
| phantom-deps | phantom-dep:@arbocollab/ag-grid-ui-components | AI (phantom-deps): workspace:* monorepo sibling; phantom-dep is expected. | ai | |
| phantom-deps | phantom-dep:driver.js | AI (phantom-deps): Peer dependency pattern; referenced in config files only. | ai | |
| dependencies | unvetted-dep:@arbocollab/vue-ag-grid | AI (dependencies): workspace:* monorepo sibling; not an external dependency. | ai | |
| dependencies | unvetted-dep:@arbocollab/api-services | AI (dependencies): workspace:* monorepo sibling; not an external dependency. | ai | |
| dependencies | unvetted-dep:@arbocollab/ag-grid-ui-components | AI (dependencies): workspace:* monorepo sibling; not an external dependency. | ai | |
| phantom-deps | phantom-dep:vue | AI (phantom-deps): Peer dependency pattern in Vue component library; referenced in config files. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 1.1.72 | 15 / 19 | |
| 1.0.36 | 13 / 19 | |
| 0.1.78 | 15 / 19 | |
| 0.1.77 | 15 / 19 | |
| 0.0.184 | 14 / 19 | |
| 0.0.171 | 14 / 19 | |
| 0.0.165 | 14 / 19 | |
| 0.0.164 | 14 / 19 | |
| 0.0.163 | 14 / 19 | |
| 0.0.136 | 13 / 19 | |
| 0.0.96 | 13 / 19 | |
| 0.0.93 | 13 / 19 | |
| 0.0.92 | 13 / 19 | |
| 0.0.78 | 13 / 19 | |
| 0.0.56 | 13 / 19 | |
| 0.0.43 | 13 / 19 | |
| 0.0.34 | 13 / 19 | |
| 0.0.18 | 13 / 19 | |
| 0.0.13 | 13 / 19 | |
| 0.0.11 | 13 / 19 | |
| 0.0.7 | 13 / 19 |
v1.0.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.78
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.77
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.184
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.171
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.165
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.164
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.163
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.136
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.96
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.93
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.92
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.78
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.56
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.