@elliemae/pui-cli
ICE MT UI Platform CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:rimraf | AI (phantom-deps): Build-tool dependency; stable for this package. | ai | |
| phantom-deps | phantom-dep:raf | AI (phantom-deps): Build-tool dependency; referenced in config files, stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:pino | AI (phantom-deps): Config-referenced logging dependency; stable for this package. | ai | |
| phantom-deps | phantom-dep:plop | AI (phantom-deps): Config-referenced code-generation tool; stable for this package. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Config-referenced utility; stable for this package. | ai | |
| phantom-deps | phantom-dep:husky | AI (phantom-deps): Git-hooks tool referenced in config; stable for this package. | ai | |
| phantom-deps | phantom-dep:jsdoc | AI (phantom-deps): Documentation tool referenced in config; stable for this package. | ai | |
| phantom-deps | phantom-dep:lerna | AI (phantom-deps): Monorepo tool referenced in config; stable for this package. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): Config-referenced date library; stable for this package. | ai | |
| phantom-deps | phantom-dep:prisma | AI (phantom-deps): Config-referenced ORM tool; stable for this package. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Config-referenced; used via CLI and type-checking, not direct imports. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework plugin; loaded by convention via .babelrc config. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): Type definitions; loaded by convention, not imported. | ai | |
| phantom-deps | phantom-dep:@storybook/react | AI (phantom-deps): Storybook plugin loaded by config; stable for this package. | ai | |
| phantom-deps | phantom-dep:webpack-cli | AI (phantom-deps): Build tool referenced in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:eslint | AI (phantom-deps): Linter referenced in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:msw | AI (phantom-deps): Build/test tool referenced in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:pug | AI (phantom-deps): Template loader referenced in webpack config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:tsx | AI (phantom-deps): CLI invoked via scripts; stable pattern for this package. | ai | |
| provenance | no-provenance | AI (provenance): Large established corporate package; no provenance is consistent with all prior versions. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 8.62.1 | 222 / 6 | |
| 8.62.0 | 222 / 6 | |
| 8.55.6 | 224 / 6 | |
| 8.55.5 | 224 / 6 | |
| 8.55.3 | 224 / 6 | |
| 8.53.0 | 224 / 6 | |
| 8.52.4 | 224 / 6 | |
| 8.52.3 | 224 / 6 | |
| 8.52.2 | 223 / 6 | |
| 8.52.1 | 223 / 6 | |
| 8.52.0 | 223 / 6 |
v8.62.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: encw.dev.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.55.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.55.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.55.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.53.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.52.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.52.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.52.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.52.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.52.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.