@linktr.ee/create-link-app
Create a Link App on Linktr.ee.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@testing-library/user-event | AI (phantom-deps): Framework-scoped test dep; not directly imported by convention in this scaffold. | ai | |
| phantom-deps | phantom-dep:storybook-addon-turbo-build | AI (phantom-deps): Storybook config-only reference; stable false positive for this scaffold package. | ai | |
| phantom-deps | phantom-dep:@storybook/addon-interactions | AI (phantom-deps): Storybook config-only reference; stable false positive for this scaffold package. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:style-loader | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:postcss-loader | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:styled-components | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-help | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@storybook/addon-links | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/line-clamp | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:storybook-addon-designs | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@storybook/addon-actions | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@storybook/addon-postcss | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-native-builder-bob | AI (phantom-deps): Platform-specific build tool devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@storybook/addon-essentials | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@storybook/builder-webpack5 | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@storybook/manager-webpack5 | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@testing-library/react | AI (phantom-deps): Framework-scoped devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:css-loader | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 2.2.5 | 57 / 19 | |
| 2.2.3 | 57 / 19 | |
| 2.2.2 | 57 / 19 | |
| 2.2.0 | 54 / 19 | |
| 2.1.0 | 54 / 19 | |
| 2.0.0 | 53 / 19 |
v2.2.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.