← Home

@muil/viewer

Visit [Muil Docs.](https://docs.muil.io)

8
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

shahaf.muilnir.avrahamnirne

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:babel-plugin-react-css-modules AI (phantom-deps): Babel plugin loaded by convention via babel config, not direct import; stable pattern for this package. ai
phantom-deps phantom-dep:@babel/plugin-proposal-class-properties AI (phantom-deps): Framework-scoped babel plugin loaded by convention; stable for this package. ai
phantom-deps phantom-dep:@babel/plugin-proposal-optional-chaining AI (phantom-deps): Framework-scoped babel plugin loaded by convention; stable for this package. ai
phantom-deps phantom-dep:@babel/plugin-proposal-nullish-coalescing-operator AI (phantom-deps): Framework-scoped babel plugin loaded by convention; stable for this package. ai
phantom-deps phantom-dep:file-loader AI (phantom-deps): Webpack loader referenced in config files by convention. ai
phantom-deps phantom-dep:webpack-cli AI (phantom-deps): CLI tool referenced in scripts by convention, not directly imported. ai
phantom-deps phantom-dep:babel-loader AI (phantom-deps): Webpack loader loaded by convention in webpack config. ai
phantom-deps phantom-dep:style-loader AI (phantom-deps): Webpack loader referenced in config files by convention. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in minified webpack bundle output; standard pattern for bundled template/React code in this package. ai
phantom-deps phantom-dep:@babel/preset-react AI (phantom-deps): Babel preset loaded by convention via babelrc config. ai
phantom-deps phantom-dep:@babel/preset-typescript AI (phantom-deps): Babel preset loaded by convention via babelrc config. ai
phantom-deps phantom-dep:@muil/templates-starter-kit AI (phantom-deps): Same org scope; used as a dev/demo dependency, not directly imported in library code. ai
phantom-deps phantom-dep:@babel/preset-env AI (phantom-deps): Babel preset loaded by convention via babelrc config. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads user-supplied webpack config by resolved path; standard middleware pattern for this package. ai
phantom-deps phantom-dep:css-loader AI (phantom-deps): Webpack loader referenced in config files by convention, not directly imported. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped babel package loaded by convention. ai

Versions (showing 8 of 8)

Version Deps Published
5.0.4 21 / 3
5.0.3 21 / 3
5.0.2 21 / 3
5.0.1 21 / 3
5.0.0 21 / 3
4.1.13 25 / 3
4.1.12 25 / 3
4.1.11 25 / 3

v5.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.