← Home

@live-change/db-admin

51
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

m8

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@fortawesome/fontawesome-free AI (phantom-deps): Config-referenced UI dependency; stable pattern for this package. ai
dependencies unvetted-dep:prism-es6 AI (dependencies): Syntax highlighting library; no malicious indicators; stable dep in this UI admin package. ai
dependencies unvetted-dep:v-shared-element AI (dependencies): Vue shared element transition library; no malicious indicators; pinned version in a UI package. ai
npm-metadata no-description AI (npm-metadata): Long-lived package with 394 versions; missing description is a cosmetic issue. ai
bogus-package bogus-package AI (bogus-package): Frontend app package; missing description/keywords/repo URL is cosmetic, not indicative of malice given 394-version history. ai
phantom-deps phantom-dep:primeicons AI (phantom-deps): Icon font referenced in config; stable false positive. ai
phantom-deps phantom-dep:compression AI (phantom-deps): Server middleware referenced indirectly; stable false positive. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Frontend dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:serve-static AI (phantom-deps): Server dep referenced indirectly; stable false positive. ai
phantom-deps phantom-dep:@live-change/dao AI (phantom-deps): Same-org dep; stable false positive. ai
phantom-deps phantom-dep:vue-prism-editor AI (phantom-deps): Frontend dep in config; stable false positive. ai
phantom-deps phantom-dep:codeceptjs-assert AI (phantom-deps): Test dep referenced in config; stable false positive. ai
semgrep semgrep:eval-usage AI (semgrep): eval used on internally-constructed code in a path parser; not user-controlled external input. ai
phantom-deps phantom-dep:tailwindcss-primeui AI (phantom-deps): CSS plugin in config; stable false positive. ai
phantom-deps phantom-dep:javascript-stringify AI (phantom-deps): Utility dep in config; stable false positive. ai
phantom-deps phantom-dep:serialize-javascript AI (phantom-deps): SSR utility in config; stable false positive. ai
phantom-deps phantom-dep:@live-change/dao-sockjs AI (phantom-deps): Same-org dep; stable false positive. ai
phantom-deps phantom-dep:@live-change/dao-message AI (phantom-deps): Same-org dep; stable false positive. ai
phantom-deps phantom-dep:@live-change/dao-websocket AI (phantom-deps): Same-org dep; stable false positive. ai
phantom-deps phantom-dep:rollup-plugin-node-builtins AI (phantom-deps): Build tool in config; stable false positive. ai
phantom-deps phantom-dep:vue3-scroll-border AI (phantom-deps): Frontend dep in config; stable false positive. ai
phantom-deps phantom-dep:prismjs AI (phantom-deps): CSS/config-referenced dep in a frontend package; stable false positive. ai
phantom-deps phantom-dep:cross-env AI (phantom-deps): Used in npm scripts only; phantom-dep false positive for this package. ai
phantom-deps phantom-dep:primeflex AI (phantom-deps): Frontend CSS framework referenced in config; stable false positive. ai
phantom-deps phantom-dep:prism-es6 AI (phantom-deps): Referenced in config files; stable false positive for this package. ai

Versions (showing 51 of 119)

View all versions
Version Deps Published
0.9.209 32 / 12
0.9.205 32 / 12
0.9.204 32 / 12
0.9.203 32 / 12
0.9.201 32 / 12
0.9.200 32 / 12
0.9.199 32 / 12
0.9.198 32 / 12
0.9.197 32 / 12
0.9.196 32 / 12
0.9.195 32 / 12
0.9.194 32 / 12
0.9.193 32 / 12
0.9.191 32 / 12
0.9.190 32 / 12
0.9.189 32 / 12
0.9.188 32 / 12
0.9.186 32 / 12
0.9.185 32 / 12
0.9.184 32 / 12
0.9.183 32 / 12
0.9.182 32 / 12
0.9.181 32 / 12
0.9.180 32 / 12
0.9.179 32 / 12
0.9.177 32 / 12
0.9.176 32 / 12
0.9.175 32 / 12
0.9.174 32 / 12
0.9.173 32 / 12
0.9.171 32 / 12
0.9.169 32 / 12
0.9.167 32 / 12
0.9.166 32 / 12
0.9.165 32 / 12
0.9.164 32 / 12
0.9.163 32 / 12
0.9.162 32 / 12
0.9.161 32 / 12
0.9.160 32 / 12
0.9.159 32 / 12
0.9.158 32 / 12
0.9.157 32 / 12
0.9.156 32 / 12
0.9.155 32 / 12
0.9.154 32 / 12
0.9.153 32 / 12
0.9.152 32 / 12
0.9.151 32 / 12
0.9.150 32 / 12
0.9.148 32 / 12

v0.9.209

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.205

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.203

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.201

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.200

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.199

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.198

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.197

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.196

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.195

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.194

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.193

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.191

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.190

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.189

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.188

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.186

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.185

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.184

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.183

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.182

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.181

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.180

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.179

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.177

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.176

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.175

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.174

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.173

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.171

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.169

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.167

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.166

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.165

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.164

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.163

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.162

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.161

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.160

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.159

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.158

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.157

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.156

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.155

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.154

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.153

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.152

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.151

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.150

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.148

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.