← Home

@designcrowd/app.maker

A collection of Maker/Designer applications

42
Versions
UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

pmcmanus-dccamgarveyphi-designcrowdfletcherdesigncrowd-npm-ciylairdcjringermaverick.crisostomoantonyfrancis-dcjames.joungbrookeherbertmelanielisboadcrebeccarosejim.jiangdanielmaycamichaeljohnstonemhillier98kushalpoudyalailenitee18npne.bibekemillie-thiseltonjb-dcgavinwoodsdavidcarsonreshma.reghuseanxiao-designcrowdall22.helmanhaiderali.designbudinmonzonjason-designcomstackrfmikaela.iquina

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:what-input AI (phantom-deps): Referenced via config; stable FP. ai
phantom-deps phantom-dep:date-utils AI (phantom-deps): Referenced via config; stable FP. ai
phantom-deps phantom-dep:body-parser AI (phantom-deps): Referenced via config; stable FP. ai
phantom-deps phantom-dep:express AI (phantom-deps): Server dep referenced via config; stable FP. ai
phantom-deps phantom-dep:mssql AI (phantom-deps): Large app package; deps referenced via config files, not direct imports — stable FP for this package. ai
phantom-deps phantom-dep:config AI (phantom-deps): Referenced in config files; stable FP. ai
phantom-deps phantom-dep:raygun AI (phantom-deps): Error tracking dep referenced via config; stable FP. ai
phantom-deps phantom-dep:raygun4js AI (phantom-deps): Referenced via config; stable FP. ai
phantom-deps phantom-dep:motion-ui AI (phantom-deps): Referenced via config; stable FP. ai
phantom-deps phantom-dep:chroma-js AI (phantom-deps): Referenced via config; stable FP. ai
phantom-deps phantom-dep:slugify AI (phantom-deps): Referenced via config; stable FP. ai
phantom-deps phantom-dep:http-errors AI (phantom-deps): Referenced via config; stable FP. ai
phantom-deps phantom-dep:es6-promise AI (phantom-deps): Referenced via config; stable FP. ai
phantom-deps phantom-dep:chance AI (phantom-deps): Referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@storybook/react AI (phantom-deps): Storybook config reference; stable false positive for this package. ai
phantom-deps phantom-dep:foundation-sites AI (phantom-deps): Config-referenced dep; stable false positive. ai
phantom-deps phantom-dep:pinia AI (phantom-deps): Vue ecosystem dep referenced in config files; stable false positive for this package. ai
phantom-deps phantom-dep:canvas AI (phantom-deps): Referenced in config files; stable false positive for this package. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): Config-referenced dep; stable false positive. ai
phantom-deps phantom-dep:vuedraggable AI (phantom-deps): Config-referenced Vue dep; stable false positive. ai
phantom-deps phantom-dep:@designcrowd/design-system-configuration AI (phantom-deps): Same-org dep referenced in config; stable false positive. ai
provenance no-provenance AI (provenance): Private org package; provenance not expected for internal npm CI publishing. ai
phantom-deps phantom-dep:click-outside-vue3 AI (phantom-deps): Referenced in config files; stable false positive for this package. ai
phantom-deps phantom-dep:serialize-error AI (phantom-deps): Referenced in config files; stable false positive for this package. ai
phantom-deps phantom-dep:vue3-shortkey AI (phantom-deps): Referenced in config files; stable false positive for this package. ai
phantom-deps phantom-dep:vue-router AI (phantom-deps): Referenced in config files; stable false positive for this package. ai
phantom-deps phantom-dep:portal-vue AI (phantom-deps): Referenced in config files; stable false positive for this package. ai
phantom-deps phantom-dep:file-type AI (phantom-deps): Referenced in config files; stable false positive for this package. ai
phantom-deps phantom-dep:core-js AI (phantom-deps): Known implicit runtime dependency; stable false positive. ai
phantom-deps phantom-dep:jquery AI (phantom-deps): Declared in dependencies; referenced in config files, stable false positive for this package. ai
license uncommon-license:UNLICENSED AI (license): Private/proprietary package; UNLICENSED is intentional for internal org packages. ai

Versions (showing 42 of 42)

Version Deps Published
5.6.273 31 / 72
5.6.267 31 / 72
5.6.263 31 / 71
5.6.261 31 / 71
5.6.257 32 / 71
5.6.256 32 / 71
5.6.255 32 / 71
5.6.252 32 / 71
5.6.250 32 / 71
5.6.248 32 / 71
5.6.247 32 / 71
5.6.239 37 / 69
5.6.227 37 / 69
5.6.226 37 / 69
5.6.221 37 / 69
5.6.219 37 / 69
5.6.210 37 / 69
5.6.201 37 / 69
5.6.196 37 / 69
5.6.191 37 / 69
5.6.190 37 / 69
5.6.177 37 / 69
5.6.173 37 / 69
5.6.163 38 / 69
5.6.153 38 / 69
5.6.144 39 / 69
5.6.133 38 / 69
5.6.127 38 / 69
5.6.85 38 / 69
5.6.74 38 / 69
5.6.73 38 / 69
5.6.71 38 / 69
5.6.69 38 / 69
5.6.58 38 / 69
5.6.51 38 / 69
5.6.50 38 / 69
5.6.48 38 / 69
5.6.45 38 / 69
5.6.34 38 / 69
5.6.18 36 / 70
5.6.17 36 / 70
5.6.12 56 / 93

v5.6.273

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.267

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.263

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.261

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.257

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.256

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.255

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.252

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.250

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.248

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.247

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.239

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.227

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.226

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.221

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.219

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.210

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.201

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.196

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.191

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.190

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.177

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.173

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.163

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.153

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.144

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.133

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.127

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.85

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.74

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.73

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.71

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.69

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.51

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.50

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.48

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.6.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.