← Home

@nice-move/all-in-vue

[![npm][npm-badge]][npm-url] [![github][github-badge]][github-url] ![node][node-badge]

15
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

airkro

Keywords

eslintnice-moveprettierstylelint

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Established package with consistent publishing history; lack of provenance is common and not a risk signal here. ai
phantom-deps phantom-dep:@nice-move/cli AI (phantom-deps): Same-org monorepo dep; not directly imported by design as a tooling config package. ai
phantom-deps phantom-dep:@nice-move/prettier-config AI (phantom-deps): Same-org monorepo dep; re-exported config, not directly imported. ai
phantom-deps phantom-dep:@nice-move/stylelint-config AI (phantom-deps): Same-org monorepo dep; re-exported config, not directly imported. ai
provenance slsa-provenance AI (provenance): CI/CD published with Sigstore SLSA attestation; stable supply chain signal for this package. ai
phantom-deps phantom-dep:@nice-move/tsconfig AI (phantom-deps): Exposed as a re-exported tsconfig.json path, not a direct JS import; stable false positive for this package. ai

Versions (showing 15 of 15)

Version Deps Published
0.8.4 5 / 0
0.7.3 5 / 0
0.6.31 5 / 0
0.6.19 5 / 0
0.6.12 5 / 0
0.6.11 5 / 0
0.6.1 5 / 0
0.5.0 5 / 0
0.4.28 5 / 0
0.4.27 5 / 0
0.4.26 5 / 0
0.4.25 5 / 0
0.4.24 5 / 0
0.4.23 5 / 0
0.4.22 5 / 0

v0.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.