@ditojs/admin
Dito.js Admin is a schema based admin interface for Dito.js Server, featuring auto-generated views and forms and built with Vue.js
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@tiptap/extensions | AI (phantom-deps): Config-level tiptap reference; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tiptap/pm | AI (phantom-deps): Tiptap packages are peer/config-referenced in a Vue admin UI; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:@tiptap/core | AI (phantom-deps): Same as @tiptap/pm — config-level reference in a rich-text editor integration. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-text-style | AI (phantom-deps): Config-level tiptap reference; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vueuse/integrations | AI (phantom-deps): Config-level reference; stable false positive for this Vue admin package. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-list | AI (phantom-deps): Config-level tiptap reference; stable false positive. | ai | |
| provenance | no-provenance | AI (provenance): Long-established package with consistent publish history; provenance absence is not a risk signal here. | ai |
Versions (showing 41 of 41)
| Version | Deps | Published |
|---|---|---|
| 2.99.1 | 2 / 3 | |
| 2.99.0 | 2 / 3 | |
| 2.98.0 | 2 / 3 | |
| 2.97.0 | 2 / 3 | |
| 2.96.0 | 2 / 3 | |
| 2.95.0 | 2 / 3 | |
| 2.93.0 | 2 / 3 | |
| 2.91.0 | 2 / 3 | |
| 2.90.0 | 2 / 3 | |
| 2.89.0 | 2 / 3 | |
| 2.88.0 | 2 / 3 | |
| 2.87.0 | 2 / 3 | |
| 2.86.0 | 2 / 3 | |
| 2.85.2 | 45 / 3 | |
| 2.83.0 | 45 / 3 | |
| 2.78.0 | 45 / 3 | |
| 2.77.1 | 45 / 3 | |
| 2.73.3 | 45 / 3 | |
| 2.73.0 | 45 / 3 | |
| 2.70.0 | 45 / 3 | |
| 2.62.0 | 45 / 3 | |
| 2.61.0 | 45 / 3 | |
| 2.60.0 | 45 / 3 | |
| 2.59.0 | 45 / 3 | |
| 2.58.2 | 45 / 3 | |
| 2.58.1 | 45 / 3 | |
| 2.58.0 | 45 / 3 | |
| 2.57.0 | 43 / 3 | |
| 2.56.0 | 43 / 3 | |
| 2.55.0 | 43 / 3 | |
| 2.54.0 | 43 / 3 | |
| 2.53.0 | 43 / 3 | |
| 2.52.0 | 43 / 3 | |
| 2.51.2 | 43 / 3 | |
| 2.51.0 | 43 / 3 | |
| 2.50.0 | 43 / 3 | |
| 2.49.1 | 43 / 3 | |
| 2.49.0 | 43 / 3 | |
| 2.48.0 | 43 / 3 | |
| 2.47.0 | 43 / 3 | |
| 2.46.1 | 43 / 3 |
v2.99.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.99.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.98.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.96.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.95.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.93.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.91.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.90.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.89.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.88.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.87.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.86.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.85.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.83.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.78.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.77.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.73.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.73.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.70.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.62.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.61.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.60.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.59.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.58.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.58.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.58.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.57.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.56.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.55.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.54.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.53.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.52.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.51.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.51.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.50.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.49.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.49.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.48.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.47.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.46.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.