@dathra/components
Web Components high-level API for Dathra framework
10
Versions
MPL-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
takuma-ru
Keywords
dathraweb-componentscustom-elementsshadow-domframeworkfrontendjavascripttypescript
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/implementation-CSedSfgD.mjs | AI (source-diff): Standard tsdown build output; minified but fully readable logic, no malicious patterns. | ai | |
| provenance | publisher-changed | AI (provenance): Package explicitly uses GitHub Actions CI/CD with SLSA provenance; automated publisher is expected and attested. | ai | |
| license | weak-copyleft-license:MPL-2.0 | AI (license): MPL-2.0 is the declared license for the dathra framework; stable across versions. | ai |