← Home

@jx3box/jx3box-ui

JX3BOX Vue3 UI

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

rx6x3zvawqkaviilee

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:url AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:dayjs AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:katex AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:jquery AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:core-js AI (phantom-deps): Known implicit runtime dep; stable false positive. ai
phantom-deps phantom-dep:viewerjs AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:js-base64 AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:qrcode.vue AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:sortablejs AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:v-code-diff AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:highlight.js AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:vuedraggable AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:@jx3box/jx3box-data AI (phantom-deps): Same-org dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:postcss-safe-parser AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:@jx3box/jx3box-macro AI (phantom-deps): Same-org dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:@tinymce/tinymce-vue AI (phantom-deps): Config-referenced dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:@jx3box/jx3box-editor AI (phantom-deps): Same-org dep in a Vue UI library; stable false positive. ai
phantom-deps phantom-dep:@jx3box/jx3box-talent AI (phantom-deps): Same-org dep in a Vue UI library; stable false positive. ai

Versions (showing 51 of 84)

View all versions
Version Deps Published
2.2.20 29 / 27
2.2.19 29 / 27
2.2.18 29 / 27
2.2.17 29 / 27
2.2.16 29 / 27
2.2.15 29 / 27
2.2.14 29 / 27
2.2.13 29 / 27
2.2.12 29 / 27
2.2.11 29 / 27
2.2.10 29 / 27
2.2.9 29 / 27
2.2.8 29 / 27
2.2.7 29 / 27
2.2.6 29 / 27
2.2.5 29 / 27
2.2.4 29 / 27
2.2.3 29 / 27
2.2.2 29 / 27
2.2.1 29 / 27
2.2.0 29 / 27
2.1.20 29 / 27
2.1.19 29 / 27
2.1.18 29 / 27
2.1.17 29 / 27
2.1.16 29 / 27
2.1.15 29 / 27
2.1.14 29 / 27
2.1.13 29 / 27
2.1.12 29 / 27
2.1.11 29 / 27
2.1.10 29 / 27
2.1.9 29 / 27
2.1.8 29 / 27
2.1.7 29 / 27
2.1.6 29 / 27
2.1.5 29 / 27
2.1.4 29 / 27
2.1.3 29 / 27
2.1.2 29 / 27
2.1.1 29 / 27
2.1.0 29 / 27
2.0.42 29 / 27
2.0.41 29 / 27
2.0.40 29 / 27
2.0.39 29 / 27
2.0.38 29 / 27
2.0.37 29 / 27
2.0.36 29 / 27
2.0.35 29 / 27
2.0.34 29 / 27

v2.2.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.40

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.38

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.