← Home

@live-change/image-frontend

51
Versions
BSD-3-Clause
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

m8

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:rollup-plugin-node-builtins AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:rollup-plugin-visualizer AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:@live-change/dao-websocket AI (phantom-deps): Same-org monorepo dep; stable FP. ai
phantom-deps phantom-dep:@live-change/image-service AI (phantom-deps): Same-org monorepo dep; stable FP. ai
phantom-deps phantom-dep:primevue AI (phantom-deps): Config-file-only reference in a frontend package; stable false positive for this package. ai
phantom-deps phantom-dep:cross-env AI (phantom-deps): Used in npm scripts only; not a runtime import. Stable FP. ai
phantom-deps phantom-dep:primeflex AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:primeicons AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:compression AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:pretty-bytes AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:serve-static AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:get-port-sync AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:@live-change/cli AI (phantom-deps): Same-org monorepo dep used in scripts; stable FP. ai
phantom-deps phantom-dep:@live-change/dao AI (phantom-deps): Same-org monorepo dep; stable FP. ai
phantom-deps phantom-dep:v-shared-element AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:codeceptjs-assert AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:vue3-scroll-border AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:serialize-javascript AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:@live-change/dao-vue3 AI (phantom-deps): Same-org monorepo dep; stable FP. ai
npm-metadata no-description AI (npm-metadata): Consistent with @live-change internal package pattern; not a malware indicator here. ai
provenance no-provenance AI (provenance): No provenance across the entire @live-change ecosystem; stable false positive for this publisher. ai
bogus-package bogus-package AI (bogus-package): Internal monorepo package from established @live-change org; sparse metadata is a consistent pattern across their 440+ versions. ai

Versions (showing 51 of 134)

View all versions
Version Deps Published
0.9.209 27 / 7
0.9.208 27 / 7
0.9.207 27 / 7
0.9.206 27 / 7
0.9.205 27 / 7
0.9.204 27 / 7
0.9.203 27 / 7
0.9.201 27 / 7
0.9.200 27 / 7
0.9.199 27 / 7
0.9.198 27 / 7
0.9.197 27 / 7
0.9.196 27 / 7
0.9.195 27 / 7
0.9.194 27 / 7
0.9.193 27 / 7
0.9.192 27 / 7
0.9.191 27 / 7
0.9.190 27 / 7
0.9.189 27 / 7
0.9.188 27 / 7
0.9.187 27 / 7
0.9.186 27 / 7
0.9.185 27 / 7
0.9.184 27 / 7
0.9.183 27 / 7
0.9.182 27 / 7
0.9.181 27 / 7
0.9.180 27 / 7
0.9.179 27 / 7
0.9.177 27 / 7
0.9.176 27 / 7
0.9.175 27 / 7
0.9.174 27 / 7
0.9.173 27 / 7
0.9.171 27 / 7
0.9.169 27 / 7
0.9.167 27 / 7
0.9.166 27 / 7
0.9.165 27 / 7
0.9.164 27 / 7
0.9.163 27 / 7
0.9.162 27 / 7
0.9.161 27 / 7
0.9.160 27 / 7
0.9.159 27 / 7
0.9.158 27 / 7
0.9.157 27 / 7
0.9.156 27 / 7
0.9.155 27 / 7
0.9.154 27 / 7

v0.9.209

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.208

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.207

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.206

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.205

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.203

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.201

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.200

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.199

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.198

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.197

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.196

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.195

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.194

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.193

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.192

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.191

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.190

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.189

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.188

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.187

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.186

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.185

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.184

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.183

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.182

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.181

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.180

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.179

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.177

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.176

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.175

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.174

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.173

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.171

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.169

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.167

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.166

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.165

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.164

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.163

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.162

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.161

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.160

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.159

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.158

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.157

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.156

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.155

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.154

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.