@mml-io/3d-web-client-core
18
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
marcuslongmuir
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@tweakpane/core | AI (dependencies): @tweakpane/core is a well-known UI component library; pinned version use is benign for this package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Long-lived scoped package in a known org; missing description is a cosmetic issue, not a malware indicator. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped org package with 251 versions and trusted publisher; missing metadata is cosmetic, not indicative of spam/malware. | ai | |
| phantom-deps | phantom-dep:@tweakpane/core | AI (phantom-deps): @tweakpane/core is a peer/config-level dep of tweakpane; not directly imported but legitimately declared. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 0.28.0 | 5 / 9 | |
| 0.27.1 | 5 / 9 | |
| 0.27.0 | 5 / 9 | |
| 0.26.1 | 5 / 3 | |
| 0.26.0 | 5 / 3 | |
| 0.25.0 | 17 / 3 | |
| 0.24.2 | 15 / 3 | |
| 0.24.1 | 15 / 3 | |
| 0.24.0 | 15 / 3 | |
| 0.23.4 | 15 / 3 | |
| 0.23.3 | 15 / 3 | |
| 0.23.2 | 15 / 3 | |
| 0.23.1 | 15 / 3 | |
| 0.23.0 | 15 / 3 | |
| 0.22.0 | 10 / 1 | |
| 0.21.0 | 10 / 1 | |
| 0.20.0 | 10 / 1 | |
| 0.16.0 | 9 / 1 |
v0.21.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.20.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.16.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.