← Home

@davidsneighbour/postcss-config

PostCSS configuration for use in @davidsneighbour projects.

2
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

davidsneighbour

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:doiuse AI (phantom-deps): PostCSS config package; plugins are referenced in config exports, not imported directly. ai
phantom-deps phantom-dep:pixrem AI (phantom-deps): PostCSS config package; plugins are referenced in config exports, not imported directly. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): PostCSS config package; postcss is a peer dependency used by consumers, not imported directly. ai
phantom-deps phantom-dep:postcss-cli AI (phantom-deps): PostCSS config package; plugins are referenced in config exports, not imported directly. ai
phantom-deps phantom-dep:postcss-import AI (phantom-deps): PostCSS config package; plugins are referenced in config exports, not imported directly. ai
phantom-deps phantom-dep:postcss-loader AI (phantom-deps): PostCSS config package; plugins are referenced in config exports, not imported directly. ai
phantom-deps phantom-dep:postcss-nesting AI (phantom-deps): PostCSS config package; plugins are referenced in config exports, not imported directly. ai
phantom-deps phantom-dep:@davidsneighbour/browserslist-config AI (phantom-deps): Same-org config package; referenced in config exports rather than direct imports. ai

Versions (showing 2 of 2)

Version Deps Published
2026.0.6 12 / 0
2026.0.1 12 / 0

v2026.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.