← Home

@meistrari/tela-build

Look at the [Nuxt 3 documentation](https://nuxt.com/docs/getting-started/introduction) to learn more.

32
Versions
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

0xthierryrjmunhozamorim33henrykunhrodrigo_lgczaghiianfiremanmatheusvellonethullyocunharenanllm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Established package with 87 versions; no provenance is a process gap, not a security indicator for this package. ai
phantom-deps phantom-dep:vue-input-otp AI (phantom-deps): Consistent with this package's pattern of convention-loaded Nuxt deps; not directly imported but used via framework config. ai
phantom-deps phantom-dep:@vueuse/components AI (phantom-deps): VueUse component library; consistent with Nuxt/Vue ecosystem usage pattern in this package. ai
publish-pattern new-deps-added AI (publish-pattern): pdfjs-dist is a well-established Mozilla library; addition is benign for a UI component build package. ai
dependencies unvetted-dep:@unocss/nuxt AI (dependencies): @unocss/nuxt is a well-known UnoCSS Nuxt integration; no malicious indicators. ai
dependencies unvetted-dep:@iconify-json/ph AI (dependencies): @iconify-json/ph is a standard Iconify icon set; no malicious indicators. ai
phantom-deps phantom-dep:@nuxt/fonts AI (phantom-deps): Nuxt convention-loaded module; not directly imported by design. ai
phantom-deps phantom-dep:@unocss/nuxt AI (phantom-deps): Nuxt module loaded via config convention, not direct import. ai
phantom-deps phantom-dep:@floating-ui/vue AI (phantom-deps): Declared in dependencies; UI utility used via convention. ai
phantom-deps phantom-dep:@number-flow/vue AI (phantom-deps): Declared in dependencies; used via convention. ai
phantom-deps phantom-dep:tailwindcss-animate AI (phantom-deps): Declared in dependencies; Tailwind plugin loaded via config. ai
phantom-deps phantom-dep:import-in-the-middle AI (phantom-deps): Declared in dependencies; Nuxt/Nitro instrumentation dep. ai
phantom-deps phantom-dep:@internationalized/date AI (phantom-deps): Declared in dependencies; used via convention in component library. ai
phantom-deps phantom-dep:resize-observer-polyfill AI (phantom-deps): Declared in dependencies; polyfill loaded via convention. ai
phantom-deps phantom-dep:@internationalized/number AI (phantom-deps): Declared in dependencies; used via convention. ai
phantom-deps phantom-dep:@fontsource-variable/inter AI (phantom-deps): Declared in dependencies; font loaded via CSS/config convention. ai
phantom-deps phantom-dep:@fontsource-variable/geist-mono AI (phantom-deps): Declared in dependencies; font loaded via CSS/config convention. ai
phantom-deps phantom-dep:@iconify-json/ph AI (phantom-deps): Declared in dependencies; icon set loaded by Nuxt icon module. ai
phantom-deps phantom-dep:gsap AI (phantom-deps): Declared in dependencies; used via config/convention in Nuxt layer, not direct import. ai
phantom-deps phantom-dep:motion AI (phantom-deps): Declared in dependencies; used via config/convention in Nuxt layer. ai
phantom-deps phantom-dep:nitropack AI (phantom-deps): Declared in dependencies; Nuxt framework peer, loaded by convention. ai
phantom-deps phantom-dep:vue-router AI (phantom-deps): Standard Nuxt peer dependency, loaded by framework convention. ai
phantom-deps phantom-dep:number-flow AI (phantom-deps): Declared in dependencies; used via config/convention. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Declared in dependencies; standard VueUse usage in Nuxt layer. ai
phantom-deps phantom-dep:lucide-vue-next AI (phantom-deps): Declared in dependencies; icon library used via convention. ai
install-scripts install-script:postinstall AI (install-scripts): nuxt prepare is a standard Nuxt type-generation command; benign and expected for Nuxt-based packages. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): Used by nuxt prepare and ts-morph tooling; config-level reference is expected. ai
phantom-deps phantom-dep:motion-v AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this Nuxt package. ai
phantom-deps phantom-dep:radix-vue AI (phantom-deps): Vue component library referenced in config; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@nuxtjs/tailwindcss AI (phantom-deps): Nuxt module loaded by convention, not direct import. ai
phantom-deps phantom-dep:@nuxtjs/color-mode AI (phantom-deps): Nuxt module loaded by convention, not direct import. ai
phantom-deps phantom-dep:@vueuse/nuxt AI (phantom-deps): Nuxt module loaded by convention, not direct import. ai
phantom-deps phantom-dep:@nuxt/icon AI (phantom-deps): Framework-scoped Nuxt module loaded by convention, not direct import. ai

Versions (showing 32 of 32)

Version Deps Published
1.42.0 43 / 16
1.41.0 42 / 16
1.40.0 41 / 16
1.38.2 40 / 16
1.38.1 40 / 16
1.38.0 40 / 16
1.37.0 40 / 16
1.36.0 40 / 16
1.35.1 40 / 16
1.34.1 40 / 16
1.33.0 40 / 16
1.30.3 40 / 16
1.30.2 40 / 16
1.30.0 40 / 16
1.29.2 40 / 16
1.29.0 40 / 16
1.27.1 40 / 16
1.27.0 39 / 16
1.26.0 39 / 16
1.25.3 39 / 16
1.25.2 39 / 16
1.13.0 37 / 16
1.11.1 37 / 16
1.10.0 38 / 16
1.9.1 38 / 16
1.9.0 38 / 16
1.5.1 38 / 16
1.3.1 38 / 16
1.3.0 38 / 16
1.0.3 38 / 16
1.0.2 38 / 16
1.0.1 38 / 16

v1.42.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.41.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.40.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.2

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: nuxt prepare

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.38.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.36.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.35.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.34.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.33.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.30.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.30.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.30.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.29.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.29.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.25.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.25.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.