@feedmepos/mf-financing
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/Application-Dso_sbxU.js | AI (source-diff): Standard Vite minified bundle; readable imports and logic, not obfuscated malware. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects bundled financing module, consistent with normal feature growth for this package. | ai | |
| source-diff | obfuscated-file:dist/Application-CyMgeDII.js | AI (source-diff): Standard Vite minified bundle for a Vue/Pinia app; readable identifiers, no obfuscation indicators. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal org micro-frontend package; sparse metadata is expected for private scoped packages in this ecosystem. | ai | |
| dependencies | unvetted-dep:@feedmepos/core | AI (dependencies): Internal @feedmepos scoped dependency; expected for this org's packages. | ai | |
| phantom-deps | phantom-dep:libphonenumber-js | AI (phantom-deps): Declared in config for micro-frontend shared deps; consistent pattern across this org's packages. | ai | |
| phantom-deps | phantom-dep:i18next-browser-languagedetector | AI (phantom-deps): Declared in config for micro-frontend shared deps; consistent pattern across this org's packages. | ai | |
| phantom-deps | phantom-dep:vue-signature-pad | AI (phantom-deps): Declared in config for micro-frontend shared deps; consistent pattern across this org's packages. | ai | |
| phantom-deps | phantom-dep:i18next-http-backend | AI (phantom-deps): Declared in config for micro-frontend shared deps; consistent pattern across this org's packages. | ai | |
| phantom-deps | phantom-dep:vue-advanced-cropper | AI (phantom-deps): Declared in config for micro-frontend shared deps; consistent pattern across this org's packages. | ai | |
| phantom-deps | phantom-dep:vue-country-flag-next | AI (phantom-deps): Declared in config for micro-frontend shared deps; consistent pattern across this org's packages. | ai | |
| phantom-deps | phantom-dep:qrcode.vue | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:change-case | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:google-maps | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:i18next-vue | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:jszip | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:vuedraggable | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:@casl/ability | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:rasterizehtml | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:vue-pdf-embed | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:vue3-lottie | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Micro-frontend bundle pattern; deps declared for module federation, not direct import. | ai | |
| phantom-deps | phantom-dep:jspdf | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:jsurl | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:firebase | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:vue-i18n | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:dinero.js | AI (phantom-deps): Same micro-frontend bundle pattern. | ai | |
| phantom-deps | phantom-dep:file-saver | AI (phantom-deps): Same micro-frontend bundle pattern. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 0.0.6 | 36 / 30 | |
| 0.0.5 | 36 / 30 | |
| 0.0.3 | 36 / 30 | |
| 0.0.2 | 36 / 30 |
v0.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.