@meistrari/tela-build
Look at the [Nuxt 3 documentation](https://nuxt.com/docs/getting-started/introduction) to learn more.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Established package with 87 versions; no provenance is a process gap, not a security indicator for this package. | ai | |
| phantom-deps | phantom-dep:vue-input-otp | AI (phantom-deps): Consistent with this package's pattern of convention-loaded Nuxt deps; not directly imported but used via framework config. | ai | |
| phantom-deps | phantom-dep:@vueuse/components | AI (phantom-deps): VueUse component library; consistent with Nuxt/Vue ecosystem usage pattern in this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): pdfjs-dist is a well-established Mozilla library; addition is benign for a UI component build package. | ai | |
| dependencies | unvetted-dep:@unocss/nuxt | AI (dependencies): @unocss/nuxt is a well-known UnoCSS Nuxt integration; no malicious indicators. | ai | |
| dependencies | unvetted-dep:@iconify-json/ph | AI (dependencies): @iconify-json/ph is a standard Iconify icon set; no malicious indicators. | ai | |
| phantom-deps | phantom-dep:@nuxt/fonts | AI (phantom-deps): Nuxt convention-loaded module; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:@unocss/nuxt | AI (phantom-deps): Nuxt module loaded via config convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@floating-ui/vue | AI (phantom-deps): Declared in dependencies; UI utility used via convention. | ai | |
| phantom-deps | phantom-dep:@number-flow/vue | AI (phantom-deps): Declared in dependencies; used via convention. | ai | |
| phantom-deps | phantom-dep:tailwindcss-animate | AI (phantom-deps): Declared in dependencies; Tailwind plugin loaded via config. | ai | |
| phantom-deps | phantom-dep:import-in-the-middle | AI (phantom-deps): Declared in dependencies; Nuxt/Nitro instrumentation dep. | ai | |
| phantom-deps | phantom-dep:@internationalized/date | AI (phantom-deps): Declared in dependencies; used via convention in component library. | ai | |
| phantom-deps | phantom-dep:resize-observer-polyfill | AI (phantom-deps): Declared in dependencies; polyfill loaded via convention. | ai | |
| phantom-deps | phantom-dep:@internationalized/number | AI (phantom-deps): Declared in dependencies; used via convention. | ai | |
| phantom-deps | phantom-dep:@fontsource-variable/inter | AI (phantom-deps): Declared in dependencies; font loaded via CSS/config convention. | ai | |
| phantom-deps | phantom-dep:@fontsource-variable/geist-mono | AI (phantom-deps): Declared in dependencies; font loaded via CSS/config convention. | ai | |
| phantom-deps | phantom-dep:@iconify-json/ph | AI (phantom-deps): Declared in dependencies; icon set loaded by Nuxt icon module. | ai | |
| phantom-deps | phantom-dep:gsap | AI (phantom-deps): Declared in dependencies; used via config/convention in Nuxt layer, not direct import. | ai | |
| phantom-deps | phantom-dep:motion | AI (phantom-deps): Declared in dependencies; used via config/convention in Nuxt layer. | ai | |
| phantom-deps | phantom-dep:nitropack | AI (phantom-deps): Declared in dependencies; Nuxt framework peer, loaded by convention. | ai | |
| phantom-deps | phantom-dep:vue-router | AI (phantom-deps): Standard Nuxt peer dependency, loaded by framework convention. | ai | |
| phantom-deps | phantom-dep:number-flow | AI (phantom-deps): Declared in dependencies; used via config/convention. | ai | |
| phantom-deps | phantom-dep:@vueuse/core | AI (phantom-deps): Declared in dependencies; standard VueUse usage in Nuxt layer. | ai | |
| phantom-deps | phantom-dep:lucide-vue-next | AI (phantom-deps): Declared in dependencies; icon library used via convention. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): nuxt prepare is a standard Nuxt type-generation command; benign and expected for Nuxt-based packages. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Used by nuxt prepare and ts-morph tooling; config-level reference is expected. | ai | |
| phantom-deps | phantom-dep:motion-v | AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this Nuxt package. | ai | |
| phantom-deps | phantom-dep:radix-vue | AI (phantom-deps): Vue component library referenced in config; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:@nuxtjs/tailwindcss | AI (phantom-deps): Nuxt module loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@nuxtjs/color-mode | AI (phantom-deps): Nuxt module loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@vueuse/nuxt | AI (phantom-deps): Nuxt module loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@nuxt/icon | AI (phantom-deps): Framework-scoped Nuxt module loaded by convention, not direct import. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 1.42.0 | 43 / 16 | |
| 1.41.0 | 42 / 16 | |
| 1.40.0 | 41 / 16 | |
| 1.38.2 | 40 / 16 | |
| 1.38.1 | 40 / 16 | |
| 1.38.0 | 40 / 16 | |
| 1.37.0 | 40 / 16 | |
| 1.36.0 | 40 / 16 | |
| 1.35.1 | 40 / 16 | |
| 1.34.1 | 40 / 16 | |
| 1.33.0 | 40 / 16 | |
| 1.30.3 | 40 / 16 | |
| 1.30.2 | 40 / 16 | |
| 1.30.0 | 40 / 16 | |
| 1.29.2 | 40 / 16 | |
| 1.29.0 | 40 / 16 | |
| 1.27.1 | 40 / 16 | |
| 1.27.0 | 39 / 16 | |
| 1.26.0 | 39 / 16 | |
| 1.25.3 | 39 / 16 | |
| 1.25.2 | 39 / 16 | |
| 1.13.0 | 37 / 16 | |
| 1.11.1 | 37 / 16 | |
| 1.10.0 | 38 / 16 | |
| 1.9.1 | 38 / 16 | |
| 1.9.0 | 38 / 16 | |
| 1.5.1 | 38 / 16 | |
| 1.3.1 | 38 / 16 | |
| 1.3.0 | 38 / 16 | |
| 1.0.3 | 38 / 16 | |
| 1.0.2 | 38 / 16 | |
| 1.0.1 | 38 / 16 |
v1.42.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.2
2 findingsScript: nuxt prepare
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.36.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.30.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.30.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.29.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.29.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.27.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.26.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.25.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.25.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.