← Home

@live-change/frontend-base

6
Versions
BSD-3-Clause
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

m8

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@vue/compiler-sfc AI (phantom-deps): Framework-scoped build dep; stable false positive. ai
phantom-deps phantom-dep:@primevue/themes AI (phantom-deps): UI framework peer dep; stable false positive. ai
phantom-deps phantom-dep:@dotenvx/dotenvx AI (phantom-deps): Env tooling dep; stable false positive. ai
phantom-deps phantom-dep:primeflex AI (phantom-deps): CSS framework peer dep; stable false positive. ai
phantom-deps phantom-dep:vue-shadow-dom AI (phantom-deps): Vue plugin peer dep; stable false positive. ai
phantom-deps phantom-dep:get-port-sync AI (phantom-deps): Dev tooling dep; stable false positive. ai
phantom-deps phantom-dep:unhead AI (phantom-deps): Frontend framework peer dep declared for consumer use; stable false positive for this package. ai
phantom-deps phantom-dep:serve-static AI (phantom-deps): Server middleware; stable false positive. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Vue composables peer dep; stable false positive. ai
phantom-deps phantom-dep:compression AI (phantom-deps): Server middleware dep used in scripts; stable false positive. ai
phantom-deps phantom-dep:@unhead/ssr AI (phantom-deps): SSR peer dep; stable false positive. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): Build tooling dep; stable false positive. ai
phantom-deps phantom-dep:primeicons AI (phantom-deps): Icon font peer dep; stable false positive. ai
phantom-deps phantom-dep:codeceptjs-assert AI (phantom-deps): Test tooling dep; stable false positive. ai
phantom-deps phantom-dep:tailwindcss AI (phantom-deps): CSS framework referenced in config files; stable FP for this scaffold. ai
phantom-deps phantom-dep:boxicons AI (phantom-deps): CSS icon library referenced in config/templates, not directly imported in JS — stable false positive for this scaffold package. ai
phantom-deps phantom-dep:vue-gtag AI (phantom-deps): Analytics plugin wired via config; not directly imported — stable FP for this package. ai
phantom-deps phantom-dep:vue-meta AI (phantom-deps): Meta plugin used via config convention; stable FP. ai
phantom-deps phantom-dep:cross-env AI (phantom-deps): Used in npm scripts, not imported — stable FP. ai
phantom-deps phantom-dep:vue-router AI (phantom-deps): Framework convention; loaded by plugin, not direct import — stable FP. ai
phantom-deps phantom-dep:markdown-it AI (phantom-deps): Markdown plugin ecosystem wired via config; stable FP. ai
bogus-package bogus-package AI (bogus-package): Internal framework base package; missing description/repo is cosmetic, not a spam/malware indicator for this established package. ai
phantom-deps phantom-dep:@live-change/password-authentication-service AI (phantom-deps): Same-org package; stable false positive. ai
phantom-deps phantom-dep:@live-change/secret-link-service AI (phantom-deps): Same-org package; stable false positive. ai
phantom-deps phantom-dep:@live-change/secret-code-service AI (phantom-deps): Same-org package; stable false positive. ai
phantom-deps phantom-dep:@live-change/security-frontend AI (phantom-deps): Same-org package; stable false positive. ai
phantom-deps phantom-dep:@live-change/session-service AI (phantom-deps): Same-org package; stable false positive. ai
phantom-deps phantom-dep:@live-change/email-service AI (phantom-deps): Same-org package; stable false positive. ai
phantom-deps phantom-dep:@live-change/user-service AI (phantom-deps): Same-org package; stable false positive. ai
phantom-deps phantom-dep:@live-change/dao-websocket AI (phantom-deps): Same-org package; stable false positive. ai
phantom-deps phantom-dep:@live-change/dao-message AI (phantom-deps): Same-org package; stable false positive. ai
phantom-deps phantom-dep:@live-change/dao-sockjs AI (phantom-deps): Same-org package; stable false positive. ai
phantom-deps phantom-dep:@live-change/dao AI (phantom-deps): Same-org package; phantom-dep heuristic false positive for this framework. ai
phantom-deps phantom-dep:@live-change/cli AI (phantom-deps): Same-org package used via config/CLI, not direct import; stable pattern for this package. ai

Versions (showing 6 of 6)

Version Deps Published
0.9.204 84 / 8
0.9.193 84 / 8
0.9.169 84 / 8
0.9.165 84 / 8
0.9.163 84 / 8
0.9.77 84 / 7

v0.9.193

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.169

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.165

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.163

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.77

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.