@live-change/survey-frontend
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:pica | AI (phantom-deps): Config-level dep for frontend app; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:primevue | AI (phantom-deps): UI library peer dep in frontend scaffold; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:vue-i18n | AI (phantom-deps): i18n peer dep in frontend scaffold; stable false positive. | ai | |
| phantom-deps | phantom-dep:cross-env | AI (phantom-deps): Used in npm scripts, not imported; stable false positive. | ai | |
| phantom-deps | phantom-dep:primeflex | AI (phantom-deps): CSS utility peer dep; stable false positive for this frontend scaffold. | ai | |
| phantom-deps | phantom-dep:primeicons | AI (phantom-deps): Icon peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:compression | AI (phantom-deps): Server middleware dep used in server/start.js; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vueuse/core | AI (phantom-deps): Vue composables peer dep; stable false positive for this frontend scaffold. | ai | |
| phantom-deps | phantom-dep:pretty-bytes | AI (phantom-deps): Utility dep referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:serve-static | AI (phantom-deps): Server middleware; stable false positive. | ai | |
| phantom-deps | phantom-dep:vue | AI (phantom-deps): Frontend scaffold pattern; vue is a peer dep referenced in vite config, not directly imported. | ai | |
| phantom-deps | phantom-dep:@dotenvx/dotenvx | AI (phantom-deps): Used in npm scripts via CLI, not imported; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/dao | AI (phantom-deps): Same-org peer dep; stable false positive for this monorepo package. | ai | |
| phantom-deps | phantom-dep:v-shared-element | AI (phantom-deps): Vue plugin peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:codeceptjs-assert | AI (phantom-deps): Test utility; stable false positive. | ai | |
| phantom-deps | phantom-dep:vue3-scroll-border | AI (phantom-deps): Vue component peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@codemirror/language | AI (phantom-deps): Editor peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:serialize-javascript | AI (phantom-deps): SSR utility; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/dao-vue3 | AI (phantom-deps): Same-org peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@live-change/db-client | AI (phantom-deps): Same-org peer dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:get-port-sync | AI (phantom-deps): Dev server utility; stable false positive. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 0.9.201 | 58 / 7 | |
| 0.9.200 | 58 / 7 | |
| 0.9.199 | 58 / 7 | |
| 0.9.198 | 58 / 7 | |
| 0.9.197 | 58 / 7 | |
| 0.9.193 | 58 / 7 | |
| 0.9.190 | 58 / 7 | |
| 0.9.189 | 58 / 7 | |
| 0.9.186 | 58 / 7 | |
| 0.9.182 | 58 / 7 | |
| 0.9.164 | 58 / 7 | |
| 0.9.163 | 58 / 7 | |
| 0.9.159 | 58 / 7 | |
| 0.9.154 | 58 / 7 | |
| 0.9.152 | 58 / 7 | |
| 0.9.147 | 58 / 7 | |
| 0.9.138 | 58 / 7 | |
| 0.9.134 | 58 / 7 | |
| 0.9.130 | 58 / 7 | |
| 0.9.126 | 58 / 7 | |
| 0.9.124 | 58 / 7 | |
| 0.9.119 | 58 / 7 | |
| 0.9.111 | 58 / 7 | |
| 0.9.105 | 58 / 7 | |
| 0.9.102 | 58 / 7 | |
| 0.9.99 | 58 / 7 | |
| 0.9.98 | 58 / 7 | |
| 0.9.96 | 58 / 7 | |
| 0.9.89 | 58 / 7 | |
| 0.9.88 | 58 / 7 | |
| 0.9.82 | 58 / 7 | |
| 0.9.78 | 58 / 7 | |
| 0.9.76 | 58 / 7 | |
| 0.9.72 | 58 / 7 |
v0.9.201
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.200
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.199
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.198
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.197
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.193
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.190
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.189
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.186
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.182
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.164
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.163
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.159
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.154
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.152
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.147
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.138
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.134
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.130
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.126
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.124
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.119
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.111
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.105
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.102
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.99
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.98
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.96
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.89
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.88
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.82
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.78
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.76
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.9.72
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.