← Home

@kyro-cms/admin

Admin dashboard for Kyro CMS

13
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

danieldozie

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@kyro-cms/astro AI (dependencies): Same-org monorepo sibling package pinned to identical version. ai
phantom-deps phantom-dep:@kyro-cms/astro AI (phantom-deps): Same-org sibling; likely used via integration wiring, not direct import. ai
phantom-deps phantom-dep:@tiptap/pm AI (phantom-deps): Peer dep of tiptap extensions, loaded indirectly. ai
phantom-deps phantom-dep:graphiql AI (phantom-deps): Framework-scoped, loaded by convention. ai
phantom-deps phantom-dep:astro-loading-indicator AI (phantom-deps): Astro integration loaded via config. ai
phantom-deps phantom-dep:idb-keyval AI (phantom-deps): Used via storage driver config, not direct import. ai
phantom-deps phantom-dep:swup AI (phantom-deps): Used via config, standard for Astro transition libs. ai
phantom-deps phantom-dep:@codemirror/state AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. ai
phantom-deps phantom-dep:@udecode/plate-dnd AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. ai
phantom-deps phantom-dep:@portabletext/types AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. ai
phantom-deps phantom-dep:@uiw/codemirror-theme-dracula AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. ai
phantom-deps phantom-dep:@types/pg AI (phantom-deps): Type-only dep; framework-scoped, stable false positive for this package. ai
phantom-deps phantom-dep:@codemirror/view AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. ai
phantom-deps phantom-dep:slate AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. ai
phantom-deps phantom-dep:platejs AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. ai
phantom-deps phantom-dep:slate-react AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. ai
phantom-deps phantom-dep:slate-history AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. ai
phantom-deps phantom-dep:@platejs/dnd AI (phantom-deps): Config-file reference pattern; stable for this CMS editor package. ai
phantom-deps phantom-dep:@graphiql/react AI (phantom-deps): Config-file reference pattern; stable for this CMS admin package. ai
source-diff obfuscated-file:dist/index.cjs AI (source-diff): Sample shows standard bundled/minified output (tsup), not true obfuscation. ai
source-diff obfuscated-file:dist/index.js AI (source-diff): Sample shows standard bundled/minified output (tsup), not true obfuscation. ai
phantom-deps phantom-dep:@tailwindcss/vite AI (phantom-deps): Vite plugin referenced in Astro config; config-only usage is expected. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom is referenced in Astro config/JSX context; stable false positive for this Astro-based package. ai
phantom-deps phantom-dep:@astrojs/react AI (phantom-deps): Astro React integration referenced in config; config-only usage is expected. ai
phantom-deps phantom-dep:@astrojs/node AI (phantom-deps): Astro adapter referenced in astro.config; config-only usage is expected. ai
phantom-deps phantom-dep:tailwindcss AI (phantom-deps): tailwindcss is used via @tailwindcss/vite config integration, not a direct import; stable false positive for this package. ai

Versions (showing 13 of 13)

Version Deps Published
0.12.18 59 / 9
0.12.15 58 / 9
0.12.8 58 / 9
0.3.2 49 / 9
0.3.1 49 / 9
0.3.0 49 / 9
0.2.1 52 / 7
0.1.7 50 / 7
0.1.6 9 / 3
0.1.5 9 / 3
0.1.4 9 / 3
0.1.3 9 / 3
0.1.2 9 / 3

v0.12.18

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: danieldozie.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.