← Home

@dwidge/crud-api-react

A CRUD API library with swr for React applications.

44
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

dwidgedev

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher change from dwidge to dwidgedev is consistent with same-author account migration; repo URL unchanged, no malicious signals present. ai
maintainer-change maintainer-takeover AI (maintainer-change): dwidge and dwidgedev share the same namespace prefix and dwidgedev has a clean 555-day track record with 251 approved packages; this appears to be a legitimate author account consolidation. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainer dwidgedev is the same author under a new account; stable accept for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of dwidge is consistent with account consolidation to dwidgedev; no hostile takeover indicators. ai
provenance no-provenance AI (provenance): Established publisher with clean history; lack of Sigstore provenance is a process gap, not a security indicator for this package. ai
provenance missing-githead AI (provenance): Publisher dwidgedev has a strong track record (251 approved/0 rejected). Missing gitHead reflects a CI/publish environment change, not a security concern for this package. ai
bogus-package bogus-package AI (bogus-package): Sparse README and missing keywords are cosmetic issues; package is from a trusted publisher with 44 versions and a clean track record. ai
dependencies unvetted-dep:@dwidge/query-axios-zod AI (dependencies): Published by the same trusted publisher (dwidgedev, 249 approved / 0 rejected); low risk for this package. ai
dependencies unvetted-dep:swr AI (dependencies): swr is a well-known, widely-used React data-fetching library maintained by Vercel; unvetted flag is a false positive for this package. ai

Versions (showing 44 of 44)

Version Deps Published
0.0.49 0 / 4
0.0.47 0 / 4
0.0.46 0 / 4
0.0.45 0 / 4
0.0.44 0 / 4
0.0.43 0 / 4
0.0.42 0 / 4
0.0.41 0 / 4
0.0.40 0 / 4
0.0.39 0 / 4
0.0.38 0 / 4
0.0.37 0 / 4
0.0.36 0 / 4
0.0.34 0 / 4
0.0.32 0 / 4
0.0.31 0 / 4
0.0.30 0 / 4
0.0.29 0 / 4
0.0.28 0 / 4
0.0.27 0 / 4
0.0.26 0 / 4
0.0.25 0 / 4
0.0.24 0 / 4
0.0.23 0 / 4
0.0.22 0 / 4
0.0.21 0 / 4
0.0.20 0 / 4
0.0.19 0 / 4
0.0.18 0 / 4
0.0.17 0 / 4
0.0.16 0 / 4
0.0.15 0 / 4
0.0.14 0 / 4
0.0.13 0 / 4
0.0.12 0 / 4
0.0.11 0 / 4
0.0.10 0 / 4
0.0.9 0 / 4
0.0.8 5 / 4
0.0.7 5 / 4
0.0.6 5 / 4
0.0.3 0 / 3
0.0.2 0 / 3
0.0.1 0 / 3