@itcase/config
ITCase Config
28
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
arkadiy_zamaraev
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@lerna-lite/run | AI (phantom-deps): Config package; lerna tools referenced in config files, not direct imports. | ai | |
| phantom-deps | phantom-dep:rollup-plugin-peer-deps-external | AI (phantom-deps): Config package; rollup plugins referenced in config files, not direct imports. | ai | |
| phantom-deps | phantom-dep:rollup-preserve-directives | AI (phantom-deps): Config package; rollup plugins referenced in config files, not direct imports. | ai | |
| phantom-deps | phantom-dep:rollup-plugin-copy | AI (phantom-deps): Config package; rollup plugins referenced in config files, not direct imports. | ai | |
| phantom-deps | phantom-dep:rollup-plugin-dts | AI (phantom-deps): Config package; rollup plugins referenced in config files, not direct imports. | ai | |
| phantom-deps | phantom-dep:@lerna-lite/watch | AI (phantom-deps): Config package; lerna tools referenced in config files, not direct imports. | ai | |
| phantom-deps | phantom-dep:@lerna-lite/list | AI (phantom-deps): Config package; lerna tools referenced in config files, not direct imports. | ai | |
| phantom-deps | phantom-dep:@lerna-lite/exec | AI (phantom-deps): Config package; lerna tools referenced in config files, not direct imports. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Package distributes configs; adding commitlint tooling deps is consistent with its purpose and both packages are well-established. | ai | |
| phantom-deps | phantom-dep:postcss-url | AI (phantom-deps): Config package re-exports deps via config files; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-json | AI (phantom-deps): Rollup plugins loaded by convention in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-alias | AI (phantom-deps): Rollup plugins loaded by convention in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@lerna-lite/cli | AI (phantom-deps): Config package; lerna-lite tools referenced in config files, not direct imports. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-terser | AI (phantom-deps): Rollup plugins loaded by convention in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-node-resolve | AI (phantom-deps): Rollup plugins loaded by convention in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-typescript | AI (phantom-deps): Rollup plugins loaded by convention in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-image | AI (phantom-deps): Rollup plugins loaded by convention in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@rollup/plugin-babel | AI (phantom-deps): Rollup plugins loaded by convention in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:conventional-changelog-conventionalcommits | AI (phantom-deps): Config-file package; deps referenced in configs, not imported directly. | ai | |
| phantom-deps | phantom-dep:@semantic-release/release-notes-generator | AI (phantom-deps): Config-file package; deps referenced in configs, not imported directly. | ai | |
| phantom-deps | phantom-dep:@semantic-release/git | AI (phantom-deps): Config package; deps are referenced in exported config files, not imported directly. | ai | |
| phantom-deps | phantom-dep:@commitlint/cz-commitlint | AI (phantom-deps): Config package; deps are referenced in exported config files, not imported directly. | ai | |
| phantom-deps | phantom-dep:@commitlint/config-conventional | AI (phantom-deps): Config package; deps are referenced in exported config files, not imported directly. | ai | |
| phantom-deps | phantom-dep:@semantic-release/changelog | AI (phantom-deps): Config package; deps are referenced in exported config files, not imported directly. | ai | |
| phantom-deps | phantom-dep:postcss-unit | AI (phantom-deps): Config package; deps are referenced in exported config files, not imported directly. | ai | |
| phantom-deps | phantom-dep:@commitlint/cli | AI (phantom-deps): Config package; deps are referenced in exported config files, not imported directly. | ai | |
| phantom-deps | phantom-dep:postcss-unit-processor | AI (phantom-deps): Config package; deps are referenced in exported config files, not imported directly. | ai | |
| phantom-deps | phantom-dep:postcss-color-hsla-fallback | AI (phantom-deps): Config-exporting package; deps referenced in config files, not JS imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:cssnano | AI (phantom-deps): Config-exporting package; deps referenced in config files, not JS imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:@svgr/webpack | AI (phantom-deps): Config-exporting package; deps referenced in config files, not JS imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:postcss-clamp | AI (phantom-deps): Config-exporting package; deps referenced in config files, not JS imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:postcss-loader | AI (phantom-deps): Config-exporting package; deps referenced in config files, not JS imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:postcss-mq-extract | AI (phantom-deps): Config-exporting package; deps referenced in config files, not JS imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:postcss-urlrewrite | AI (phantom-deps): Config-exporting package; deps referenced in config files, not JS imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:postcss-extend-rule | AI (phantom-deps): Config-exporting package; deps referenced in config files, not JS imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:cssnano-preset-default | AI (phantom-deps): Config-exporting package; deps referenced in config files, not JS imports. Stable pattern. | ai | |
| phantom-deps | phantom-dep:postcss-aspect-ratio-polyfill | AI (phantom-deps): Config-exporting package; deps referenced in config files, not JS imports. Stable pattern. | ai | |
| dependencies | unvetted-dep:chokidar-cli | AI (dependencies): Legitimate file-watcher CLI; stable tooling dep for this config package. | ai | |
| dependencies | unvetted-dep:rollup-plugin-peer-deps-external | AI (dependencies): Standard rollup plugin; expected in a build-tooling config package. | ai | |
| dependencies | unvetted-dep:postcss-aspect-ratio-polyfill | AI (dependencies): PostCSS plugin; consistent with this package's postcss config aggregation purpose. | ai | |
| dependencies | unvetted-dep:postcss-sort-media-queries | AI (dependencies): PostCSS plugin; consistent with this package's postcss config aggregation purpose. | ai | |
| dependencies | unvetted-dep:postcss-urlrewrite | AI (dependencies): PostCSS plugin; consistent with this package's postcss config aggregation purpose. | ai | |
| dependencies | unvetted-dep:postcss-unitlist | AI (dependencies): PostCSS plugin; consistent with this package's postcss config aggregation purpose. | ai | |
| dependencies | unvetted-dep:@lerna-lite/watch | AI (dependencies): Well-known lerna-lite monorepo tool; expected dep for a config aggregator. | ai | |
| dependencies | unvetted-dep:@lerna-lite/list | AI (dependencies): Well-known lerna-lite monorepo tool; expected dep for a config aggregator. | ai | |
| dependencies | unvetted-dep:@lerna-lite/exec | AI (dependencies): Well-known lerna-lite monorepo tool; expected dep for a config aggregator. | ai | |
| dependencies | unvetted-dep:@lerna-lite/run | AI (dependencies): Well-known lerna-lite monorepo tool; expected dep for a config aggregator. | ai | |
| dependencies | unvetted-dep:@lerna-lite/cli | AI (dependencies): Well-known lerna-lite monorepo tool; expected dep for a config aggregator. | ai | |
| phantom-deps | phantom-dep:postcss-cli | AI (phantom-deps): CLI tool referenced in config scripts, not imported. Expected for this package type. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 142 versions; lack of provenance is common and not a risk signal here. | ai | |
| phantom-deps | phantom-dep:semantic-release-lerna | AI (phantom-deps): Plugin referenced in config, not imported. | ai | |
| phantom-deps | phantom-dep:semantic-release | AI (phantom-deps): CLI tool referenced in config, not imported. | ai | |
| phantom-deps | phantom-dep:inquirer | AI (phantom-deps): Referenced in config, not imported directly. | ai | |
| phantom-deps | phantom-dep:commitizen | AI (phantom-deps): CLI tool referenced in config, not imported. | ai | |
| phantom-deps | phantom-dep:chokidar-cli | AI (phantom-deps): CLI tool referenced in config scripts, not imported. | ai | |
| phantom-deps | phantom-dep:autoprefixer | AI (phantom-deps): PostCSS plugin referenced in config files, not imported directly. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): Config-only package; deps are referenced in config files, not imported directly. Stable pattern. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 1.6.57 | 67 / 9 | |
| 1.6.56 | 67 / 9 | |
| 1.6.55 | 67 / 9 | |
| 1.6.53 | 67 / 9 | |
| 1.6.51 | 66 / 8 | |
| 1.6.48 | 66 / 8 | |
| 1.6.45 | 66 / 8 | |
| 1.6.43 | 66 / 8 | |
| 1.6.42 | 66 / 8 | |
| 1.6.41 | 66 / 8 | |
| 1.6.35 | 66 / 8 | |
| 1.6.33 | 66 / 8 | |
| 1.6.26 | 48 / 8 | |
| 1.6.25 | 48 / 8 | |
| 1.6.20 | 48 / 8 | |
| 1.6.19 | 48 / 8 | |
| 1.6.12 | 43 / 8 | |
| 1.6.9 | 43 / 8 | |
| 1.6.4 | 43 / 8 | |
| 1.6.3 | 43 / 8 | |
| 1.5.0 | 43 / 8 | |
| 1.0.80 | 42 / 9 | |
| 1.0.79 | 42 / 9 | |
| 1.0.78 | 38 / 13 | |
| 1.0.70 | 35 / 12 | |
| 1.0.65 | 33 / 14 | |
| 1.0.53 | 33 / 14 | |
| 1.0.44 | 33 / 14 |
v1.6.33
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.