@framtidtechas/cms
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped org package @framtidtechas/cms; not a typosquat of cors. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped org package @framtidtechas/cms; not a typosquat of qs. | ai | |
| phantom-deps | phantom-dep:@framtidtechas/ai | AI (phantom-deps): Monorepo sibling dep; declared as dependency, re-exported rather than directly imported. | ai | |
| phantom-deps | phantom-dep:@framtidtechas/auth | AI (phantom-deps): Monorepo sibling dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@framtidtechas/media | AI (phantom-deps): Monorepo sibling dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@framtidtechas/editor | AI (phantom-deps): Monorepo sibling dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@framtidtechas/schema | AI (phantom-deps): Monorepo sibling dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@framtidtechas/tickets | AI (phantom-deps): Monorepo sibling dep; stable false positive for this package. | ai |
Versions (showing 51 of 101)
| Version | Deps | Published |
|---|---|---|
| 1.50.1 | 17 / 8 | |
| 1.50.0 | 17 / 8 | |
| 1.49.0 | 17 / 8 | |
| 1.48.0 | 17 / 8 | |
| 1.47.25 | 17 / 8 | |
| 1.47.24 | 17 / 8 | |
| 1.47.23 | 17 / 8 | |
| 1.47.22 | 17 / 8 | |
| 1.47.21 | 17 / 8 | |
| 1.47.20 | 17 / 8 | |
| 1.47.19 | 17 / 8 | |
| 1.47.18 | 17 / 8 | |
| 1.47.17 | 17 / 8 | |
| 1.47.16 | 17 / 8 | |
| 1.47.15 | 17 / 8 | |
| 1.47.14 | 17 / 8 | |
| 1.47.13 | 17 / 8 | |
| 1.47.12 | 17 / 8 | |
| 1.47.11 | 17 / 8 | |
| 1.47.10 | 17 / 8 | |
| 1.47.8 | 17 / 8 | |
| 1.47.7 | 17 / 8 | |
| 1.47.5 | 17 / 8 | |
| 1.47.4 | 17 / 8 | |
| 1.47.3 | 17 / 8 | |
| 1.47.2 | 17 / 8 | |
| 1.47.1 | 17 / 8 | |
| 1.47.0 | 17 / 8 | |
| 1.46.12 | 17 / 8 | |
| 1.46.11 | 17 / 8 | |
| 1.46.10 | 17 / 8 | |
| 1.46.9 | 17 / 8 | |
| 1.46.8 | 17 / 8 | |
| 1.46.7 | 17 / 8 | |
| 1.46.6 | 17 / 8 | |
| 1.46.5 | 17 / 8 | |
| 1.46.4 | 17 / 8 | |
| 1.46.3 | 17 / 8 | |
| 1.46.2 | 17 / 8 | |
| 1.46.1 | 17 / 8 | |
| 1.45.0 | 17 / 8 | |
| 1.42.39 | 17 / 8 | |
| 1.42.38 | 17 / 8 | |
| 1.42.37 | 17 / 8 | |
| 1.42.36 | 17 / 8 | |
| 1.42.35 | 17 / 8 | |
| 1.42.34 | 17 / 8 | |
| 1.42.33 | 17 / 8 | |
| 1.42.32 | 17 / 8 | |
| 1.42.31 | 17 / 8 | |
| 1.42.30 | 17 / 8 |
v1.50.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.50.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.49.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.48.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.45.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.