@bildvitta/quasar-ui-asteroid
Asteroid
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Long-established org package; provenance absence is consistent across all prior versions. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): lodash-es is a declared runtime dependency; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:debug | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:gleap | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:fuse.js | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:pica | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:sortablejs | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:autonumeric | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:signature_pad | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:pdfjs-dist | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 3.19.0 | 14 / 13 | |
| 3.18.2 | 13 / 14 | |
| 3.18.1 | 13 / 14 | |
| 3.18.0 | 13 / 14 |
v3.19.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.18.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.18.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.18.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.