@hed-hog/studio
O módulo `@hed-hog/studio` é responsável pela gestão integrada de projetos de produção audiovisual, incluindo o controle de projetos, cenas, sessões de gravação, tomadas, ativos de mídia, perfis de armazenamento, incidentes, edição e publicação. Ele ofere
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@nestjs/jwt | AI (phantom-deps): NestJS peer-dep pattern; declared for consumers, not directly imported in this lib. | ai | |
| phantom-deps | phantom-dep:@nestjs/core | AI (phantom-deps): NestJS peer-dep pattern; declared for consumers, not directly imported in this lib. | ai | |
| phantom-deps | phantom-dep:@nestjs/mapped-types | AI (phantom-deps): NestJS peer-dep pattern; declared for consumers, not directly imported in this lib. | ai | |
| phantom-deps | phantom-dep:@hed-hog/core | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for monorepo peer deps. | ai | |
| phantom-deps | phantom-dep:@hed-hog/api-types | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for monorepo peer deps. | ai |
v0.0.330
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.329
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.