← Home

@live-change/user-frontend

51
Versions
BSD-3-Clause
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

m8

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@live-change/vue3-components AI (phantom-deps): Same-org peer dep; stable false positive for this monorepo package. ai
phantom-deps phantom-dep:@live-change/security-frontend AI (phantom-deps): Same-org peer dep; stable false positive for this monorepo package. ai
phantom-deps phantom-dep:vue-meta AI (phantom-deps): Frontend framework dep used via config, not direct import. ai
phantom-deps phantom-dep:cross-env AI (phantom-deps): CLI tool used in npm scripts, not imported. ai
phantom-deps phantom-dep:pluralize AI (phantom-deps): Utility dep used in config/template context. ai
phantom-deps phantom-dep:compression AI (phantom-deps): Server middleware dep used in config, not direct import. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Frontend framework dep re-exported or used in config. ai
phantom-deps phantom-dep:serve-static AI (phantom-deps): Server dep used in config context. ai
phantom-deps phantom-dep:@live-change/dao AI (phantom-deps): Same-org dep; stable false positive for this package. ai
phantom-deps phantom-dep:v-shared-element AI (phantom-deps): UI plugin dep used in config/plugin registration, not direct import. ai
phantom-deps phantom-dep:codeceptjs-assert AI (phantom-deps): Test helper dep used in test config. ai
phantom-deps phantom-dep:sass AI (phantom-deps): Frontend framework package; deps used in config/build context, not direct imports. ai
phantom-deps phantom-dep:serialize-javascript AI (phantom-deps): SSR utility dep used in config context. ai
phantom-deps phantom-dep:@live-change/dao-vue3 AI (phantom-deps): Same-org dep; stable false positive for this package. ai
phantom-deps phantom-dep:unique-names-generator AI (phantom-deps): Utility dep used in config/test context. ai
phantom-deps phantom-dep:codeceptjs-video-helper AI (phantom-deps): Test helper dep used in test config. ai
phantom-deps phantom-dep:rollup-plugin-visualizer AI (phantom-deps): Build tool dep used in vite/rollup config. ai
phantom-deps phantom-dep:@live-change/dao-websocket AI (phantom-deps): Same-org dep; stable false positive for this package. ai
phantom-deps phantom-dep:@live-change/image-frontend AI (phantom-deps): Same-org dep; stable false positive for this package. ai
phantom-deps phantom-dep:rollup-plugin-node-builtins AI (phantom-deps): Build tool dep used in vite/rollup config. ai
phantom-deps phantom-dep:vue3-scroll-border AI (phantom-deps): UI plugin dep used in config/plugin registration. ai
phantom-deps phantom-dep:wtfnode AI (phantom-deps): Dev/debug tool referenced in scripts, not imported directly. ai

Versions (showing 51 of 134)

View all versions
Version Deps Published
0.9.209 42 / 8
0.9.208 42 / 8
0.9.207 42 / 8
0.9.206 42 / 8
0.9.205 42 / 8
0.9.204 41 / 7
0.9.203 41 / 7
0.9.201 41 / 7
0.9.200 41 / 7
0.9.199 41 / 7
0.9.198 41 / 7
0.9.197 41 / 7
0.9.196 41 / 7
0.9.195 41 / 7
0.9.194 41 / 7
0.9.193 41 / 7
0.9.192 41 / 7
0.9.191 41 / 7
0.9.190 41 / 7
0.9.189 41 / 7
0.9.188 41 / 7
0.9.187 41 / 7
0.9.186 41 / 7
0.9.185 41 / 7
0.9.184 41 / 7
0.9.183 41 / 7
0.9.182 41 / 7
0.9.181 41 / 7
0.9.180 41 / 7
0.9.179 41 / 7
0.9.177 41 / 7
0.9.176 41 / 7
0.9.175 41 / 7
0.9.174 41 / 7
0.9.173 41 / 7
0.9.171 41 / 7
0.9.169 41 / 7
0.9.167 41 / 7
0.9.166 41 / 7
0.9.165 41 / 7
0.9.164 41 / 7
0.9.163 41 / 7
0.9.162 41 / 7
0.9.161 41 / 7
0.9.160 41 / 7
0.9.159 41 / 7
0.9.158 41 / 7
0.9.157 41 / 7
0.9.156 41 / 7
0.9.155 41 / 7
0.9.154 41 / 7

v0.9.209

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.208

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.207

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.206

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.205

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.204

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.203

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.201

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.200

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.199

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.198

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.197

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.196

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.195

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.194

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.193

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.192

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.191

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.190

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.189

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.188

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.187

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.186

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.185

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.184

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.183

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.182

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.181

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.180

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.179

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.177

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.176

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.175

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.174

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.173

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.171

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.169

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.167

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.166

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.165

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.164

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.163

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.162

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.161

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.160

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.159

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.158

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.157

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.156

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.155

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.154

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.