@dfosco/storyboard-core
16
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
dfosco
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:feather-icons | AI (phantom-deps): Icon library referenced in config/tooling, not directly imported — expected pattern for this UI package. | ai | |
| phantom-deps | phantom-dep:@primer/octicons | AI (phantom-deps): Icon library referenced in config/tooling, not directly imported — expected pattern for this UI package. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Iterates env to unset shell config vars from tmux environment; intentional and documented. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decodes image data with explicit size limit check; not obfuscation. | ai | |
| semgrep | semgrep:toplevel-fetch | AI (semgrep): POSTs to local canvas agent signal endpoint; not exfiltration. | ai | |
| phantom-deps | phantom-dep:html-to-image | AI (phantom-deps): Used in UI bundle build; referenced in config files as expected. | ai | |
| phantom-deps | phantom-dep:iconoir | AI (phantom-deps): Icon library bundled into dist; referenced in build config, not directly imported at runtime. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Passes env to spawned terminal process; standard pattern for pty/tmux tools. | ai |