@marianmeres/stuic
[](https://www.npmjs.com/package/@marianmeres/stuic) [](LICENSE)
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@marianmeres/countries | AI (dependencies): Same-org dep from a publisher with 85 approved packages; consistent with this package's established dependency pattern. | ai | |
| phantom-deps | phantom-dep:runed | AI (phantom-deps): SvelteKit Svelte 5 library; runed is a Svelte 5 runes utility used at component level, not directly imported in analyzed entry points. | ai | |
| phantom-deps | phantom-dep:esm-env | AI (phantom-deps): esm-env is a build-time env utility common in SvelteKit packages; not directly imported in analyzed entry points. | ai | |
| phantom-deps | phantom-dep:@marianmeres/parse-boolean | AI (phantom-deps): Same-org dependency; likely used in component internals not caught by static import analysis. | ai |
Versions (showing 51 of 306)
| Version | Deps | Published |
|---|---|---|
| 3.118.0 | 13 / 43 | |
| 3.117.0 | 13 / 43 | |
| 3.116.0 | 13 / 43 | |
| 3.115.0 | 13 / 43 | |
| 3.114.0 | 13 / 40 | |
| 3.113.0 | 13 / 40 | |
| 3.112.0 | 13 / 40 | |
| 3.111.0 | 13 / 40 | |
| 3.110.0 | 13 / 40 | |
| 3.109.0 | 13 / 40 | |
| 3.108.0 | 13 / 25 | |
| 3.107.0 | 12 / 25 | |
| 3.106.0 | 12 / 25 | |
| 3.105.0 | 12 / 25 | |
| 3.104.0 | 12 / 25 | |
| 3.103.0 | 12 / 25 | |
| 3.102.0 | 12 / 25 | |
| 3.101.1 | 12 / 25 | |
| 3.101.0 | 12 / 25 | |
| 3.100.0 | 12 / 25 | |
| 3.99.0 | 12 / 25 | |
| 3.98.0 | 12 / 25 | |
| 3.97.0 | 12 / 25 | |
| 3.96.0 | 12 / 25 | |
| 3.95.0 | 12 / 25 | |
| 3.94.4 | 12 / 25 | |
| 3.94.3 | 12 / 25 | |
| 3.94.2 | 12 / 25 | |
| 3.94.1 | 12 / 25 | |
| 3.94.0 | 12 / 25 | |
| 3.93.0 | 12 / 25 | |
| 3.92.0 | 12 / 25 | |
| 3.91.0 | 12 / 25 | |
| 3.90.0 | 12 / 25 | |
| 3.89.0 | 12 / 25 | |
| 3.88.0 | 12 / 25 | |
| 3.87.0 | 12 / 25 | |
| 3.86.0 | 12 / 25 | |
| 3.85.0 | 12 / 25 | |
| 3.84.0 | 12 / 25 | |
| 3.83.3 | 12 / 25 | |
| 3.83.2 | 12 / 25 | |
| 3.83.1 | 12 / 25 | |
| 3.83.0 | 12 / 25 | |
| 3.82.0 | 12 / 25 | |
| 3.81.0 | 12 / 25 | |
| 3.80.1 | 12 / 25 | |
| 3.80.0 | 12 / 25 | |
| 3.79.0 | 12 / 25 | |
| 3.78.0 | 12 / 25 | |
| 3.77.1 | 12 / 25 |
v3.118.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.117.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.116.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.115.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.114.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.113.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.112.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.111.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.110.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.109.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.108.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.107.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.106.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.105.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.104.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.103.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.102.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.101.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.101.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.100.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.99.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.98.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.97.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.96.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.95.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.94.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.94.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.94.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.94.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.94.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.93.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.92.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.91.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.90.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.89.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.88.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.87.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.86.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.85.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.84.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.83.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.83.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.83.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.83.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.82.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.81.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.80.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.80.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.79.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.78.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.77.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.