← Home

@firecms/core

Awesome Firebase/Firestore-based headless open-source CMS

1
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

gatti675

Keywords

firebasecmsadminadmin panelfirebase panelfirestoreheadlessheadless cmscontent manager

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:cors AI (typosquat): @firecms/core is a scoped CMS package with 915-day history; Levenshtein match to 'cors' is coincidental. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): clsx is a legitimate runtime dep in a CMS UI package; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:history AI (phantom-deps): history is a standard routing dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:react-markdown AI (phantom-deps): react-markdown is a legitimate dep in a CMS; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:react-moveable AI (phantom-deps): react-moveable is a legitimate dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:react-image-crop AI (phantom-deps): react-image-crop is a legitimate dep for a CMS with image handling; phantom-dep false positive. ai
phantom-deps phantom-dep:react-transition-group AI (phantom-deps): react-transition-group is a common UI dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:vite-plugin-static-copy AI (phantom-deps): Build-time dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:prosemirror-schema-basic AI (phantom-deps): ProseMirror dep for rich text editor; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:prosemirror-example-setup AI (phantom-deps): ProseMirror dep for rich text editor; phantom-dep heuristic false positive. ai

Versions (showing 1 of 1)

Version Deps Published
3.2.0 48 / 25