@kyro-cms/admin
Admin dashboard for Kyro CMS
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@kyro-cms/astro | AI (dependencies): Same-org monorepo sibling package pinned to identical version. | ai | |
| phantom-deps | phantom-dep:@kyro-cms/astro | AI (phantom-deps): Same-org sibling; likely used via integration wiring, not direct import. | ai | |
| phantom-deps | phantom-dep:@tiptap/pm | AI (phantom-deps): Peer dep of tiptap extensions, loaded indirectly. | ai | |
| phantom-deps | phantom-dep:graphiql | AI (phantom-deps): Framework-scoped, loaded by convention. | ai | |
| phantom-deps | phantom-dep:astro-loading-indicator | AI (phantom-deps): Astro integration loaded via config. | ai | |
| phantom-deps | phantom-dep:idb-keyval | AI (phantom-deps): Used via storage driver config, not direct import. | ai | |
| phantom-deps | phantom-dep:swup | AI (phantom-deps): Used via config, standard for Astro transition libs. | ai | |
| phantom-deps | phantom-dep:@codemirror/state | AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. | ai | |
| phantom-deps | phantom-dep:@udecode/plate-dnd | AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. | ai | |
| phantom-deps | phantom-dep:@portabletext/types | AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. | ai | |
| phantom-deps | phantom-dep:@uiw/codemirror-theme-dracula | AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. | ai | |
| phantom-deps | phantom-dep:@types/pg | AI (phantom-deps): Type-only dep; framework-scoped, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@codemirror/view | AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. | ai | |
| phantom-deps | phantom-dep:slate | AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. | ai | |
| phantom-deps | phantom-dep:platejs | AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. | ai | |
| phantom-deps | phantom-dep:slate-react | AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. | ai | |
| phantom-deps | phantom-dep:slate-history | AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. | ai | |
| phantom-deps | phantom-dep:@platejs/dnd | AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. | ai | |
| phantom-deps | phantom-dep:@graphiql/react | AI (phantom-deps): Config-file reference pattern; stable for this CMS admin package. | ai | |
| source-diff | obfuscated-file:dist/index.cjs | AI (source-diff): Sample shows standard bundled/minified output (tsup), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index.js | AI (source-diff): Sample shows standard bundled/minified output (tsup), not true obfuscation. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/vite | AI (phantom-deps): Vite plugin referenced in Astro config; config-only usage is expected. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is referenced in Astro config/JSX context; stable false positive for this Astro-based package. | ai | |
| phantom-deps | phantom-dep:@astrojs/react | AI (phantom-deps): Astro React integration referenced in config; config-only usage is expected. | ai | |
| phantom-deps | phantom-dep:@astrojs/node | AI (phantom-deps): Astro adapter referenced in astro.config; config-only usage is expected. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): tailwindcss is used via @tailwindcss/vite config integration, not a direct import; stable false positive for this package. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 0.12.18 | 59 / 9 | |
| 0.12.15 | 58 / 9 | |
| 0.12.8 | 58 / 9 | |
| 0.3.2 | 49 / 9 | |
| 0.3.1 | 49 / 9 | |
| 0.3.0 | 49 / 9 | |
| 0.2.1 | 52 / 7 | |
| 0.1.7 | 50 / 7 | |
| 0.1.6 | 9 / 3 | |
| 0.1.5 | 9 / 3 | |
| 0.1.4 | 9 / 3 | |
| 0.1.3 | 9 / 3 | |
| 0.1.2 | 9 / 3 |
v0.12.18
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: danieldozie.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.