All @karan9186/web-components versions

@karan9186/web-components @1.0.2

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
43
Risk Score
MIT
License
No
Install Scripts
1
Dependencies
5
Dev Dependencies
419.7 KB
Package Size
Published

Stencil Component Starter

Maintainers

karan9186

Dependencies (1)

PackageConstraintRegistry Status
lucide ^1.7.0 auto_approved

Dev Dependencies (5)

PackageConstraintRegistry Status
vitest ^4.0.0 auto_approved
@types/node ^22.13.5 auto_approved
@stencil/core ^4.27.1 auto_approved
@stencil/vitest ^1.8.3 auto_approved
@vitest/browser-playwright ^4.0.0 auto_approved

Transitive Dependency Tree

1 transitive deps max depth 1
  ├─ lucide ^1.7.0 → 1.17.0

Risk Dispositions (1 applicable to this version, 1 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Rule Source Disposition Author Reason
bogus-package bogus-package reject AI AI (bogus-package): README link dump + empty entry point are stable spam/phishing indicators for this package.
Show 1 disposition(s) that do not match any finding on this version
Rule Source Disposition Author Reason
unvetted-dep:@karan9186/core dependencies reject AI AI (dependencies): workspace:* constraint on an unvetted sibling dep is unresolvable and indicates an incomplete/broken publish.

SAST Findings (1)

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

Review Summary

Risk score: 43. Findings: 1 critical (+40), 1 low (+3).

Commit: f9ac6cd26354 Browse source

Published to npm: