@kompojs/core
Code Orchestration Framework - Build apps 10x faster
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:cors | AI (typosquat): '@kompojs/core' is the core package of the kompojs monorepo framework, not a typosquat of 'cors'. The levenshtein match is coincidental — 'core' vs 'cors' is a known false positive pattern. | ai | |
| phantom-deps | phantom-dep:@kompojs/kit | AI (phantom-deps): All phantom deps are within the same @kompojs org scope; this is a monorepo core package that re-exports or bundles sibling packages for consumers. | ai | |
| phantom-deps | phantom-dep:@kompojs/config | AI (phantom-deps): Same @kompojs org scope; expected monorepo dependency pattern. | ai | |
| phantom-deps | phantom-dep:@kompojs/blueprints | AI (phantom-deps): Same @kompojs org scope; expected monorepo dependency pattern. | ai | |
| phantom-deps | phantom-dep:@kompojs/blueprints-vue | AI (phantom-deps): Same @kompojs org scope; expected monorepo dependency pattern. | ai | |
| phantom-deps | phantom-dep:@kompojs/blueprints-nuxt | AI (phantom-deps): Same @kompojs org scope; expected monorepo dependency pattern. | ai | |
| phantom-deps | phantom-dep:@kompojs/blueprints-react | AI (phantom-deps): Same @kompojs org scope; expected monorepo dependency pattern. | ai | |
| phantom-deps | phantom-dep:@kompojs/blueprints-nextjs | AI (phantom-deps): Same @kompojs org scope; expected monorepo dependency pattern. | ai | |
| phantom-deps | phantom-dep:@kompojs/blueprints-express | AI (phantom-deps): Same @kompojs org scope; expected monorepo dependency pattern. | ai |
v0.1.7
2 findingsPackage name '@kompojs/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.