@bildvitta/quasar-ui-asteroid
Asteroid
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): gleap and sibling composables package fit stated UI library function. | ai | |
| dependencies | unvetted-dep:@bildvitta/composables | AI (dependencies): First-party org-scoped dependency, same publisher ecosystem. | ai | |
| provenance | no-provenance | AI (provenance): Long-established org package; provenance absence is consistent across all prior versions. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): lodash-es is a declared runtime dependency; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:fuse.js | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:pdfjs-dist | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:pica | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:autonumeric | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:signature_pad | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:sortablejs | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:debug | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:gleap | AI (phantom-deps): UI library with optional deps referenced in config; stable false positive for this package. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 3.19.0 | 14 / 13 | |
| 3.18.2 | 13 / 14 | |
| 3.18.1 | 13 / 14 | |
| 3.18.0 | 13 / 14 | |
| 3.17.0 | 13 / 14 | |
| 3.16.4 | 13 / 14 | |
| 3.16.3 | 13 / 14 | |
| 3.16.2 | 12 / 14 | |
| 3.16.0 | 12 / 14 | |
| 3.15.0 | 11 / 14 | |
| 3.14.0 | 11 / 14 | |
| 3.13.1 | 11 / 14 | |
| 3.13.0 | 11 / 14 | |
| 3.12.0 | 10 / 14 | |
| 3.11.0 | 10 / 14 |
v3.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.16.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.16.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.16.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.13.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.13.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gcarpi) than the most recent previously approved version (douglascalora) on 2023-12-27, but gcarpi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.