@mirai/core
# 1. Installation
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:@react-icons/all-files | AI (npm-metadata): Pinned to a specific react-icons release tarball; stable workaround for that package's registry distribution issue. | ai | |
| dependencies | unvetted-dep:@mirai/ui | AI (dependencies): Sibling package in the same @mirai org monorepo. | ai | |
| dependencies | unvetted-dep:@mirai/icons | AI (dependencies): Sibling package in the same @mirai org monorepo. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @mirai/core is a scoped monorepo package, not a typosquat of cors; Levenshtein match is coincidental. | ai | |
| dependencies | unvetted-dep:@mirai/services | AI (dependencies): Sibling package in the same @mirai org monorepo. | ai | |
| dependencies | unvetted-dep:@mirai/data-sources | AI (dependencies): Sibling package in the same @mirai org monorepo. | ai | |
| dependencies | unvetted-dep:@mirai/locale | AI (dependencies): Sibling package in the same @mirai org monorepo. | ai |
Versions (showing 51 of 303)
| Version | Deps | Published |
|---|---|---|
| 0.4.601 | 9 / 17 | |
| 0.4.600 | 9 / 17 | |
| 0.4.599 | 9 / 17 | |
| 0.4.598 | 9 / 17 | |
| 0.4.597 | 9 / 17 | |
| 0.4.596 | 9 / 17 | |
| 0.4.595 | 9 / 17 | |
| 0.4.594 | 9 / 17 | |
| 0.4.593 | 9 / 17 | |
| 0.4.592 | 9 / 17 | |
| 0.4.591 | 9 / 17 | |
| 0.4.590 | 9 / 17 | |
| 0.4.589 | 9 / 17 | |
| 0.4.588 | 9 / 17 | |
| 0.4.587 | 9 / 17 | |
| 0.4.586 | 9 / 17 | |
| 0.4.585 | 9 / 17 | |
| 0.4.584 | 9 / 17 | |
| 0.4.583 | 9 / 17 | |
| 0.4.582 | 9 / 17 | |
| 0.4.581 | 9 / 17 | |
| 0.4.580 | 9 / 17 | |
| 0.4.579 | 9 / 17 | |
| 0.4.578 | 9 / 17 | |
| 0.4.577 | 9 / 17 | |
| 0.4.576 | 9 / 17 | |
| 0.4.575 | 9 / 17 | |
| 0.4.574 | 9 / 17 | |
| 0.4.573 | 9 / 17 | |
| 0.4.572 | 9 / 17 | |
| 0.4.571 | 9 / 17 | |
| 0.4.570 | 9 / 17 | |
| 0.4.569 | 9 / 17 | |
| 0.4.568 | 9 / 17 | |
| 0.4.567 | 9 / 17 | |
| 0.4.566 | 9 / 17 | |
| 0.4.565 | 9 / 17 | |
| 0.4.564 | 9 / 17 | |
| 0.4.563 | 9 / 17 | |
| 0.4.562 | 9 / 17 | |
| 0.4.561 | 9 / 17 | |
| 0.4.560 | 9 / 17 | |
| 0.4.559 | 9 / 17 | |
| 0.4.558 | 9 / 17 | |
| 0.4.557 | 9 / 17 | |
| 0.4.556 | 9 / 17 | |
| 0.4.555 | 9 / 17 | |
| 0.4.554 | 9 / 17 | |
| 0.4.553 | 9 / 17 | |
| 0.4.552 | 9 / 17 | |
| 0.4.551 | 9 / 17 |
v0.4.601
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.600
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.599
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.598
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.597
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.596
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.595
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.594
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.593
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.592
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.591
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.590
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.589
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.588
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.587
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.586
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.585
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.584
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.583
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.582
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.581
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.580
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.579
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.578
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.577
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.576
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.575
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.574
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.573
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.572
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.571
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.570
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.569
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.568
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.567
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.566
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.565
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.564
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.562
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.561
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.560
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.559
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.558
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.557
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.556
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.555
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.554
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.553
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.552
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.551
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.