@awes-io/ui
User Interface (UI) components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:libphonenumber-js | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| phantom-deps | phantom-dep:hammerjs | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| phantom-deps | phantom-dep:postcss-each | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| phantom-deps | phantom-dep:@nuxtjs/axios | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| phantom-deps | phantom-dep:vue2-teleport | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| phantom-deps | phantom-dep:clipboard-copy | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| phantom-deps | phantom-dep:postcss-easings | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library; not directly imported in library code. | ai | |
| phantom-deps | phantom-dep:animejs | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| phantom-deps | phantom-dep:cookies | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| phantom-deps | phantom-dep:core-js | AI (phantom-deps): Known implicit runtime polyfill dependency; standard false positive. | ai | |
| phantom-deps | phantom-dep:croppie | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| phantom-deps | phantom-dep:prismjs | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| phantom-deps | phantom-dep:autosize | AI (phantom-deps): Declared as peer/optional dep for consumer use in a UI library. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped package @awes-io/ui; not a typosquat of uuid. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package @awes-io/ui; not a typosquat of pg. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped package @awes-io/ui; not a typosquat of qs. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped package @awes-io/ui; not a typosquat of yup. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Standard Nuxt module pattern loading project config path; not arbitrary code execution. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @awes-io/ui; not a typosquat of joi. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 2.144.7 | 29 / 35 | |
| 2.144.6 | 29 / 35 | |
| 2.144.2 | 29 / 35 | |
| 2.144.1 | 29 / 35 | |
| 2.144.0 | 29 / 35 | |
| 2.142.3 | 29 / 36 | |
| 2.142.0 | 29 / 36 | |
| 2.130.1 | 29 / 36 |
v2.144.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.144.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.144.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.144.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.144.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.142.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.142.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.130.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.