← Home

@bcc-code/component-library-vue

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

karsten.kueppernbogdanit.accountsadelinnlaurensgroeneveldu12206050jakubc-projects

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/quill-BfNQeuzX.js AI (source-diff): Quill editor bundle legitimately uses dynamic patterns; no malicious network/exec behavior. ai
source-diff obfuscated-file:dist/quill-BfNQeuzX.js AI (source-diff): Minified Quill editor bundle; expected build artifact from quill devDependency. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher is confirmed legitimate by SLSA/Sigstore attestation on the same release. ai
dependencies unvetted-dep:@bcc-code/icons-vue AI (dependencies): Same org scope as this package; expected dependency for a BCC component library. ai
dependencies unvetted-dep:primevue AI (dependencies): primevue is a well-known Vue UI framework; stable false positive for this component library. ai
phantom-deps phantom-dep:tailwindcss AI (phantom-deps): Tailwind is a build-time CSS dep referenced in config files; not directly imported in source is expected. ai
phantom-deps phantom-dep:@bcc-code/icons-vue AI (phantom-deps): Same-org icons package; re-exported or used indirectly in component library — stable false positive. ai
phantom-deps phantom-dep:@primeuix/themes AI (phantom-deps): PrimeVue theme package referenced in config/build files; phantom detection is a false positive for this component library. ai

Versions (showing 51 of 113)

View all versions
Version Deps Published
1.4.19 6 / 41
1.4.18 6 / 41
1.4.13 6 / 41
1.4.12 6 / 41
1.4.11 6 / 41
1.4.10 6 / 41
1.4.9 6 / 41
1.4.8 6 / 41
1.4.7 6 / 41
1.4.6 6 / 41
1.4.5 6 / 41
1.4.4 6 / 35
1.4.3 6 / 35
1.4.2 6 / 35
1.4.1 6 / 35
1.4.0 6 / 35
1.3.30 6 / 35
1.3.29 6 / 35
1.3.28 6 / 35
1.3.27 6 / 35
1.3.26 6 / 35
1.3.25 6 / 35
1.3.24 6 / 35
1.3.23 6 / 35
1.3.22 6 / 35
1.3.21 6 / 35
1.3.20 6 / 35
1.3.19 6 / 35
1.3.18 6 / 35
1.3.17 6 / 35
1.3.16 6 / 35
1.3.15 6 / 35
1.3.14 6 / 35
1.3.13 6 / 34
1.3.12 6 / 34
1.3.11 6 / 34
1.3.10 6 / 34
1.3.9 6 / 33
1.3.8 6 / 33
1.3.7 6 / 33
1.3.6 6 / 33
1.3.5 6 / 33
1.3.4 6 / 33
1.3.3 6 / 33
1.3.2 6 / 33
1.3.1 6 / 33
1.3.0 6 / 33
1.1.0 6 / 33
1.0.0 6 / 32
0.10.4 6 / 32
0.10.3 6 / 32

v1.4.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.