@nubase/frontend
React components and utilities for nubase
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:typo-js | AI (phantom-deps): Spellcheck library used via monaco-spellchecker integration; indirect import pattern expected. | ai | |
| phantom-deps | phantom-dep:monaco-spellchecker | AI (phantom-deps): Monaco editor plugin; indirect import pattern expected in bundled library. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): Utility library; tree-shaken imports may not appear as direct top-level imports. | ai | |
| phantom-deps | phantom-dep:react-monaco-editor | AI (phantom-deps): Monaco React wrapper; indirect import pattern expected. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): Build-time CSS tooling; referenced in config files only, not a runtime import. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): Build-time CSS tooling; referenced in config files only. | ai | |
| phantom-deps | phantom-dep:@biomejs/biome | AI (phantom-deps): Linter/formatter; used via CLI in scripts, not imported in source. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/cli | AI (phantom-deps): Build-time CLI tool; not a runtime import. | ai | |
| phantom-deps | phantom-dep:react-hotkeys-hook | AI (phantom-deps): Likely imported indirectly through re-exports; false positive for component library. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/postcss | AI (phantom-deps): Build-time PostCSS plugin; not a runtime import. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-table | AI (phantom-deps): Likely re-exported or used in component internals; false positive for component library. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-dialog | AI (phantom-deps): UI primitive likely re-exported; false positive for component library. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-tooltip | AI (phantom-deps): UI primitive likely re-exported; false positive for component library. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-separator | AI (phantom-deps): UI primitive likely re-exported; false positive for component library. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-router-devtools | AI (phantom-deps): Dev tooling dependency; false positive for component library. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 0.1.37 | 39 / 22 | |
| 0.1.25 | 37 / 22 | |
| 0.1.22 | 36 / 22 | |
| 0.1.21 | 36 / 22 | |
| 0.1.19 | 35 / 22 | |
| 0.1.18 | 35 / 22 | |
| 0.1.16 | 35 / 22 | |
| 0.1.14 | 35 / 22 | |
| 0.1.9 | 35 / 22 | |
| 0.1.6 | 35 / 22 | |
| 0.1.5 | 35 / 22 | |
| 0.1.1 | 23 / 20 |
v0.1.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.