@cabinetdocs/core
6
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
aaronmahlke
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:estree-util-value-to-estree | AI (phantom-deps): MDX/AST utility used in build pipeline config; phantom-dep fires on config-only usage. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): nuxt prepare is the standard Nuxt.js postinstall step; benign for a Nuxt-based package. | ai | |
| phantom-deps | phantom-dep:nuxt | AI (phantom-deps): nuxt is used in scripts/config files (nuxt.config.ts); phantom-dep heuristic fires on config-only usage. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Nuxt ecosystem utility; referenced in config, not directly imported in JS source. | ai | |
| phantom-deps | phantom-dep:acorn | AI (phantom-deps): Used as a parser dependency in config/build pipeline, not directly imported. | ai | |
| phantom-deps | phantom-dep:shiki | AI (phantom-deps): Syntax highlighting dep used via config; phantom-dep fires on config-only usage. | ai | |
| phantom-deps | phantom-dep:vue-router | AI (phantom-deps): Nuxt handles vue-router integration via config; not directly imported in source. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): Tailwind is configured via nuxt.config.ts/vite plugin, not directly imported. | ai | |
| phantom-deps | phantom-dep:@shikijs/core | AI (phantom-deps): Shiki sub-package used via config; phantom-dep fires on config-only usage. | ai | |
| phantom-deps | phantom-dep:@shikijs/langs | AI (phantom-deps): Shiki sub-package used via config; phantom-dep fires on config-only usage. | ai | |
| phantom-deps | phantom-dep:@shikijs/themes | AI (phantom-deps): Shiki sub-package used via config; phantom-dep fires on config-only usage. | ai | |
| phantom-deps | phantom-dep:@shikijs/engine-oniguruma | AI (phantom-deps): Shiki sub-package used via config; phantom-dep fires on config-only usage. | ai | |
| phantom-deps | phantom-dep:@shikijs/engine-javascript | AI (phantom-deps): Shiki sub-package used via config; phantom-dep fires on config-only usage. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped @cabinetdocs/core is a Vue/Vite docs framework, not a typosquat of the cors package. | ai |