← Home

@linktr.ee/create-link-app

Create a Link App on Linktr.ee.

6
Versions
UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

chase-linktreezwparkerksavmarcus-linktreejeanikaakgupta89linktreegracemccartermrachamallulinktreewrenchessnickhenrylt-zachdaniel-linktreelt_mattogleericlinktreewayne-lincolnjoshquiaponleigh-karinjaweavaben.sauszach-lin-linktreecortl.eejesse.swickhams1luzheng_linktreenash-linktreejacobimpsonlinktreedarcylinktreemason.linktreeit-appsorlandojgubmanlucabernardinogenrmirandajacoblinktree2stlasallebradleyessaadurrfu-ltjerinraisaandrii.hanetsoleksandr-kucherukedbordin-linktreejameson-linktreevancegilliescarlesltroberterdinhuangjun604aimbermanjiayaoyuhakugzocoijoe-ltreedgpookaowensaldanhamruvysjazzbassjohnsonzacmartinotolseeashwini-ltmskonovalovlindsey-warrkunal94318jszklarz-ltalexb-linktreeigor-linktreeseanwangskmarshall-ltleilenahpatrickm-linktreeduongtran_linktreejake-ltcain88ltmichaelnathangathrightcolin-linktreejessieltjuantwoeesedfrey_linktrandrii.linktr.eedenys.h.linktreelouie-bertbriceyokoyamaoleksii.sievriukov.linktreeyuanlunaalxxjohnlinktree-luthermfs780icaro1508-ltmarcelo-ltadrianbrs-lttyler-linktreezander-linktreeregnullandrersfremedyedgesneamonitakisdorit-lt2carl-deguiagalacemiguelaj-abadomegdadimblodealexzaccatalinktreekhalid_treeglorison-ltlinkns

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@testing-library/user-event AI (phantom-deps): Framework-scoped test dep; not directly imported by convention in this scaffold. ai
phantom-deps phantom-dep:storybook-addon-turbo-build AI (phantom-deps): Storybook config-only reference; stable false positive for this scaffold package. ai
phantom-deps phantom-dep:@storybook/addon-interactions AI (phantom-deps): Storybook config-only reference; stable false positive for this scaffold package. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:style-loader AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:postcss-loader AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:styled-components AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:@oclif/plugin-help AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:@storybook/addon-links AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:prettier AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:@tailwindcss/line-clamp AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:storybook-addon-designs AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:@storybook/addon-actions AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:@storybook/addon-postcss AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:react-native-builder-bob AI (phantom-deps): Platform-specific build tool devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:@storybook/addon-essentials AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:@storybook/builder-webpack5 AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:@storybook/manager-webpack5 AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:@testing-library/react AI (phantom-deps): Framework-scoped devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:css-loader AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai
phantom-deps phantom-dep:prop-types AI (phantom-deps): Config-referenced devDep in a scaffold package; stable false positive. ai

Versions (showing 6 of 6)

Version Deps Published
2.2.5 57 / 19
2.2.3 57 / 19
2.2.2 57 / 19
2.2.0 54 / 19
2.1.0 54 / 19
2.0.0 53 / 19

v2.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.