← Home

@embeddable.com/remarkable-pro

Remarkable PRO is component library to use inside of [Embeddable](https://embeddable.com/).

6
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

tom-embeddableruiribeiromisha_terevgeny-embeddablejozef_trevorsyed1995yashrajk17hjkmarshallako-hk

Keywords

embeddableembeddable-componentsembeddable-uiremarkable-componentsremarkable-ui

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): Active component library; large dist additions on minor version bumps are expected for this package. ai
dependencies unvetted-dep:@embeddable.com/core AI (dependencies): First-party dependency from the same org; stable across all versions of this package. ai
dependencies unvetted-dep:@embeddable.com/react AI (dependencies): First-party dependency from the same org; stable across all versions of this package. ai
dependencies unvetted-dep:@embeddable.com/remarkable-ui AI (dependencies): First-party dependency from the same org; stable across all versions of this package. ai
dependencies unvetted-dep:xlsx AI (dependencies): Aliased to @e965/xlsx, a known maintained fork of SheetJS; consistent usage pattern for this package. ai
phantom-deps phantom-dep:fast-equals AI (phantom-deps): Component library; deps referenced in config/re-exported, not directly imported in analyzed files. ai
phantom-deps phantom-dep:@changesets/cli AI (phantom-deps): Dev tooling dep listed in dependencies by mistake; stable false positive for this package. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): Component library; deps referenced in config/re-exported, not directly imported in analyzed files. ai
phantom-deps phantom-dep:@tabler/icons-react AI (phantom-deps): Component library; deps referenced in config/re-exported, not directly imported in analyzed files. ai
phantom-deps phantom-dep:chartjs-plugin-datalabels AI (phantom-deps): Component library; deps referenced in config/re-exported, not directly imported in analyzed files. ai
phantom-deps phantom-dep:dom-to-image-more AI (phantom-deps): Component library; deps referenced in config/re-exported, not directly imported in analyzed files. ai
phantom-deps phantom-dep:xlsx AI (phantom-deps): Component library; deps referenced in config/re-exported, not directly imported in analyzed files. ai
phantom-deps phantom-dep:dayjs AI (phantom-deps): Component library; deps referenced in config/re-exported, not directly imported in analyzed files. ai
phantom-deps phantom-dep:chroma-js AI (phantom-deps): Component library; deps referenced in config/re-exported, not directly imported in analyzed files. ai
phantom-deps phantom-dep:mergician AI (phantom-deps): Component library; deps referenced in config/re-exported, not directly imported in analyzed files. ai

Versions (showing 6 of 6)

Version Deps Published
0.3.0 15 / 26
0.2.13 15 / 26
0.2.12 15 / 26
0.2.10 15 / 26
0.2.9 15 / 26
0.2.8 15 / 26

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.