← Home

@enso-ui/forms

24
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

aocneanugandescvlad.chvraftx24manuela.mindroc

Keywords

formformsjsonrenderlessbulmavue

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@enso-ui/laravel-validation AI (dependencies): Same org scope; expected sibling dependency. ai
dependencies unvetted-dep:@enso-ui/wysiwyg AI (dependencies): Same org scope; expected sibling dependency. ai
phantom-deps phantom-dep:@fortawesome/fontawesome-free AI (phantom-deps): Config-only reference; standard pattern for icon-using UI libraries. ai
phantom-deps phantom-dep:vuex AI (phantom-deps): Peer/config-only reference typical for Vue ecosystem component libraries. ai
dependencies unvetted-dep:bulma AI (dependencies): Well-known CSS framework; stable dependency for this UI package. ai
dependencies unvetted-dep:@enso-ui/modal AI (dependencies): Same org scope; expected sibling dependency. ai
dependencies unvetted-dep:@enso-ui/divider AI (dependencies): Same org scope; expected sibling dependency. ai
phantom-deps phantom-dep:@enso-ui/select AI (phantom-deps): Same-org sibling dep; stable false positive. ai
phantom-deps phantom-dep:@enso-ui/switch AI (phantom-deps): Same-org sibling dep; stable false positive. ai
phantom-deps phantom-dep:@enso-ui/divider AI (phantom-deps): Same-org sibling dep; stable false positive. ai
phantom-deps phantom-dep:@enso-ui/datepicker AI (phantom-deps): Same-org sibling dep; stable false positive. ai
phantom-deps phantom-dep:@enso-ui/directives AI (phantom-deps): Same-org sibling dep; stable false positive. ai
phantom-deps phantom-dep:@enso-ui/laravel-validation AI (phantom-deps): Same-org sibling dep; stable false positive. ai
phantom-deps phantom-dep:@fortawesome/fontawesome-svg-core AI (phantom-deps): Icon library referenced in config; stable false positive for this component library. ai
phantom-deps phantom-dep:@fortawesome/free-solid-svg-icons AI (phantom-deps): Icon library referenced in config; stable false positive for this component library. ai
provenance no-provenance AI (provenance): Established package predating widespread provenance adoption; no other risk signals present. ai
phantom-deps phantom-dep:@enso-ui/wysiwyg AI (phantom-deps): Same-org sibling dep; stable false positive. ai
phantom-deps phantom-dep:vue AI (phantom-deps): Vue is a peer dep for component libraries; not directly imported by design. ai
phantom-deps phantom-dep:bulma AI (phantom-deps): CSS framework referenced in config/styles, not JS imports; stable false positive for this package. ai
phantom-deps phantom-dep:pinia AI (phantom-deps): State management peer dep; typical pattern for Vue component libraries. ai
phantom-deps phantom-dep:@enso-ui/tabs AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic is a stable false positive for this package. ai
phantom-deps phantom-dep:@enso-ui/modal AI (phantom-deps): Same-org sibling dep; stable false positive. ai
phantom-deps phantom-dep:@enso-ui/money AI (phantom-deps): Same-org sibling dep; stable false positive. ai
typosquat typosquat.levenshtein:cors AI (typosquat): Scoped UI package @enso-ui/forms; Levenshtein match to 'cors' is a false positive with no brand impersonation. ai
phantom-deps phantom-dep:@fortawesome/vue-fontawesome AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fires on config references, stable false positive. ai
phantom-deps phantom-dep:v-tooltip AI (phantom-deps): v-tooltip is a declared runtime dep; phantom-dep heuristic is a stable false positive for this package. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): lodash is a declared runtime dep; phantom-dep heuristic fires on config-only references, stable false positive. ai

Versions (showing 24 of 24)

Version Deps Published
4.2.0 5 / 13
4.1.21 5 / 13
4.1.19 5 / 13
4.1.18 5 / 13
4.1.17 5 / 13
4.1.16 5 / 13
4.1.15 5 / 13
4.1.14 5 / 13
4.1.13 5 / 13
4.1.12 5 / 13
4.1.11 5 / 13
4.1.10 5 / 13
4.1.9 5 / 13
4.1.8 5 / 13
4.1.7 5 / 13
4.1.6 5 / 13
4.1.5 5 / 13
4.1.4 15 / 3
4.1.3 18 / 0
4.1.2 18 / 0
4.1.1 18 / 0
4.1.0 18 / 0
4.0.0 18 / 0
3.3.3 19 / 9

v4.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.21

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.3.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.