@jay-framework/compiler-jay-html
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Framework-internal compiler package; missing metadata is normal for non-public tooling. | ai | |
| phantom-deps | phantom-dep:@jay-framework/runtime | AI (phantom-deps): Framework-scoped dep; loaded by convention in this ecosystem. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): Likely used indirectly through config tooling; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:change-case | AI (phantom-deps): Used in build pipeline, not directly imported in analyzed entry points. | ai | |
| phantom-deps | phantom-dep:pluralize | AI (phantom-deps): Used in build pipeline, not directly imported in analyzed entry points. | ai | |
| phantom-deps | phantom-dep:pegjs | AI (phantom-deps): Build-time parser generator used via CLI in build scripts, not imported directly. | ai | |
| phantom-deps | phantom-dep:@types/js-yaml | AI (phantom-deps): Type-only dependency, not imported at runtime. | ai | |
| phantom-deps | phantom-dep:@jay-framework/secure | AI (phantom-deps): Same-org package, likely loaded by convention or peer dependency pattern. | ai | |
| phantom-deps | phantom-dep:@jay-framework/component | AI (phantom-deps): Same-org package, likely loaded by convention or peer dependency pattern. | ai | |
| phantom-deps | phantom-dep:style-to-object | AI (phantom-deps): Used in build pipeline, not directly imported in analyzed entry points. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Build-time type checker invoked via tsup/tsc, not imported at runtime. | ai |
Versions (showing 51 of 58)
| Version | Deps | Published |
|---|---|---|
| 0.22.2 | 15 / 16 | |
| 0.22.1 | 15 / 16 | |
| 0.22.0 | 15 / 16 | |
| 0.21.0 | 15 / 16 | |
| 0.20.0 | 15 / 16 | |
| 0.19.8 | 15 / 16 | |
| 0.19.7 | 15 / 16 | |
| 0.19.6 | 15 / 16 | |
| 0.19.5 | 15 / 16 | |
| 0.19.4 | 15 / 16 | |
| 0.19.3 | 15 / 16 | |
| 0.19.2 | 15 / 16 | |
| 0.19.1 | 15 / 16 | |
| 0.19.0 | 15 / 16 | |
| 0.18.4 | 15 / 16 | |
| 0.18.3 | 15 / 16 | |
| 0.18.2 | 15 / 16 | |
| 0.18.1 | 15 / 16 | |
| 0.18.0 | 15 / 16 | |
| 0.17.4 | 15 / 16 | |
| 0.17.3 | 15 / 16 | |
| 0.17.2 | 15 / 16 | |
| 0.17.1 | 15 / 16 | |
| 0.17.0 | 15 / 16 | |
| 0.16.5 | 14 / 16 | |
| 0.16.4 | 14 / 16 | |
| 0.16.3 | 14 / 16 | |
| 0.16.2 | 14 / 16 | |
| 0.16.1 | 14 / 16 | |
| 0.16.0 | 14 / 16 | |
| 0.15.6 | 14 / 16 | |
| 0.15.5 | 14 / 16 | |
| 0.15.4 | 14 / 16 | |
| 0.15.3 | 14 / 16 | |
| 0.15.2 | 14 / 16 | |
| 0.15.1 | 14 / 16 | |
| 0.15.0 | 14 / 16 | |
| 0.14.0 | 14 / 16 | |
| 0.13.0 | 14 / 16 | |
| 0.12.0 | 14 / 16 | |
| 0.11.0 | 13 / 16 | |
| 0.10.0 | 13 / 16 | |
| 0.9.0 | 13 / 16 | |
| 0.8.0 | 13 / 16 | |
| 0.7.0 | 13 / 16 | |
| 0.6.9 | 13 / 16 | |
| 0.6.8 | 13 / 16 | |
| 0.6.7 | 13 / 16 | |
| 0.6.5 | 13 / 16 | |
| 0.6.4 | 13 / 16 | |
| 0.6.3 | 13 / 16 |
v0.22.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.20.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.19.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.