@live-change/frontend-base
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@vue/compiler-sfc | AI (phantom-deps): Framework-scoped build dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@primevue/themes | AI (phantom-deps): UI framework peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@dotenvx/dotenvx | AI (phantom-deps): Env tooling dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:primeflex | AI (phantom-deps): CSS framework peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:vue-shadow-dom | AI (phantom-deps): Vue plugin peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:get-port-sync | AI (phantom-deps): Dev tooling dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:unhead | AI (phantom-deps): Frontend framework peer dep declared for consumer use; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:serve-static | AI (phantom-deps): Server middleware; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vueuse/core | AI (phantom-deps): Vue composables peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:compression | AI (phantom-deps): Server middleware dep used in scripts; stable false positive. | ai | |
| phantom-deps | phantom-dep:@unhead/ssr | AI (phantom-deps): SSR peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Build tooling dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:primeicons | AI (phantom-deps): Icon font peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:codeceptjs-assert | AI (phantom-deps): Test tooling dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): CSS framework referenced in config files; stable FP for this scaffold. | ai | |
| phantom-deps | phantom-dep:boxicons | AI (phantom-deps): CSS icon library referenced in config/templates, not directly imported in JS — stable false positive for this scaffold package. | ai | |
| phantom-deps | phantom-dep:vue-gtag | AI (phantom-deps): Analytics plugin wired via config; not directly imported — stable FP for this package. | ai | |
| phantom-deps | phantom-dep:vue-meta | AI (phantom-deps): Meta plugin used via config convention; stable FP. | ai | |
| phantom-deps | phantom-dep:cross-env | AI (phantom-deps): Used in npm scripts, not imported — stable FP. | ai | |
| phantom-deps | phantom-dep:vue-router | AI (phantom-deps): Framework convention; loaded by plugin, not direct import — stable FP. | ai | |
| phantom-deps | phantom-dep:markdown-it | AI (phantom-deps): Markdown plugin ecosystem wired via config; stable FP. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal framework base package; missing description/repo is cosmetic, not a spam/malware indicator for this established package. | ai | |
| phantom-deps | phantom-dep:@live-change/password-authentication-service | AI (phantom-deps): Same-org package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/secret-link-service | AI (phantom-deps): Same-org package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/secret-code-service | AI (phantom-deps): Same-org package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/security-frontend | AI (phantom-deps): Same-org package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/session-service | AI (phantom-deps): Same-org package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/email-service | AI (phantom-deps): Same-org package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/user-service | AI (phantom-deps): Same-org package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/dao-websocket | AI (phantom-deps): Same-org package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/dao-message | AI (phantom-deps): Same-org package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/dao-sockjs | AI (phantom-deps): Same-org package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/dao | AI (phantom-deps): Same-org package; phantom-dep heuristic false positive for this framework. | ai | |
| phantom-deps | phantom-dep:@live-change/cli | AI (phantom-deps): Same-org package used via config/CLI, not direct import; stable pattern for this package. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 0.9.204 | 84 / 8 | |
| 0.9.193 | 84 / 8 | |
| 0.9.169 | 84 / 8 | |
| 0.9.165 | 84 / 8 | |
| 0.9.163 | 84 / 8 | |
| 0.9.77 | 84 / 7 |
v0.9.193
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.169
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.165
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.163
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.77
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.