@nuskin/design-components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:vuex | AI (phantom-deps): Vue component library; vuex used via config/plugin registration, not direct import. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Utility dep used indirectly in component configs; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): Date utility used via config/helpers, not direct import; stable FP. | ai | |
| phantom-deps | phantom-dep:vue-select | AI (phantom-deps): UI component registered globally, not directly imported in analyzed files. | ai | |
| phantom-deps | phantom-dep:vuex-class | AI (phantom-deps): Decorator-based vuex binding; used via class decorators in SFCs, not direct import. | ai | |
| phantom-deps | phantom-dep:vue-clipboard2 | AI (phantom-deps): Vue plugin registered globally; stable FP for this component library. | ai | |
| phantom-deps | phantom-dep:lodash.debounce | AI (phantom-deps): Utility used in component helpers; stable FP. | ai | |
| phantom-deps | phantom-dep:detectincognitojs | AI (phantom-deps): Used indirectly; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:libphonenumber-js | AI (phantom-deps): Phone validation utility; used in component logic, not direct import in analyzed files. | ai | |
| phantom-deps | phantom-dep:@nuskin/ns-account | AI (phantom-deps): Same-org scoped package; used via plugin/config pattern. | ai | |
| phantom-deps | phantom-dep:vue-class-component | AI (phantom-deps): Decorator used in SFCs; stable FP for this Vue component library. | ai | |
| phantom-deps | phantom-dep:@nuskin/nuskinjquery | AI (phantom-deps): Same-org scoped package; stable FP. | ai | |
| phantom-deps | phantom-dep:@nuskin/ns-core-styles | AI (phantom-deps): Same-org scoped styles package; stable FP. | ai | |
| phantom-deps | phantom-dep:vue-property-decorator | AI (phantom-deps): Decorator-based Vue pattern; stable FP for this component library. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 8.9.1 | 20 / 63 | |
| 8.9.0 | 20 / 63 | |
| 8.8.1 | 19 / 63 | |
| 8.8.0 | 19 / 63 | |
| 8.7.1 | 19 / 63 | |
| 8.7.0 | 19 / 63 | |
| 8.6.1 | 19 / 63 | |
| 8.6.0 | 19 / 63 |
v8.8.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.