← Home

@pie-lib/editable-html-tip-tap

8
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ed.eustacelakatosandreichilleniousandreeapescarcarlacosteaiacoshoriajustinheuer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@tiptap/extensions AI (phantom-deps): Declared dep in a bundled ESM package; heuristic false positive for this package. ai
phantom-deps phantom-dep:@tiptap/extension-list-item AI (phantom-deps): Declared dep in a bundled ESM package; heuristic false positive for this package. ai
phantom-deps phantom-dep:@pie-lib/math-rendering AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for bundled packages. ai
phantom-deps phantom-dep:@tiptap/extension-list AI (phantom-deps): Declared dep in a bundled ESM package; heuristic false positive for this package. ai
phantom-deps phantom-dep:slate-react AI (phantom-deps): Declared for config/peer use in pie-framework monorepo. ai
phantom-deps phantom-dep:slate AI (phantom-deps): Monorepo package; slate deps declared for peer/config use, not direct import. ai
phantom-deps phantom-dep:@tiptap/pm AI (phantom-deps): Declared for config/peer use in pie-framework monorepo. ai
phantom-deps phantom-dep:slate-edit-list AI (phantom-deps): Declared for config/peer use in pie-framework monorepo. ai
phantom-deps phantom-dep:slate-edit-table AI (phantom-deps): Declared for config/peer use in pie-framework monorepo. ai
phantom-deps phantom-dep:slate-prop-types AI (phantom-deps): Declared for config/peer use in pie-framework monorepo. ai
phantom-deps phantom-dep:slate-soft-break AI (phantom-deps): Declared for config/peer use in pie-framework monorepo. ai
phantom-deps phantom-dep:@material-ui/styles AI (phantom-deps): Declared for config/peer use in pie-framework monorepo. ai
phantom-deps phantom-dep:@pie-lib/math-input AI (phantom-deps): Same org scope; declared for config/peer use. ai
phantom-deps phantom-dep:slate-dev-environment AI (phantom-deps): Declared for config/peer use in pie-framework monorepo. ai
phantom-deps phantom-dep:slate-html-serializer AI (phantom-deps): Declared for config/peer use in pie-framework monorepo. ai
phantom-deps phantom-dep:slate-plain-serializer AI (phantom-deps): Declared for config/peer use in pie-framework monorepo. ai
phantom-deps phantom-dep:react-jss AI (phantom-deps): Declared dependency used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:change-case AI (phantom-deps): Declared dependency used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:react-portal AI (phantom-deps): Declared dependency used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:@pie-lib/drag AI (phantom-deps): Same-org dep; stable false positive for this package. ai
phantom-deps phantom-dep:@dnd-kit/modifiers AI (phantom-deps): Declared dependency used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:@dnd-kit/utilities AI (phantom-deps): Declared dependency used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:react-attr-converter AI (phantom-deps): Declared dependency used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:@tiptap/extension-color AI (phantom-deps): Declared dependency used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:immutable AI (phantom-deps): Declared dependency used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:to-style AI (phantom-deps): Declared dependency used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:keycode AI (phantom-deps): Declared in package.json for transitive/config use; stable false positive for this package. ai
phantom-deps phantom-dep:tippy.js AI (phantom-deps): Declared dependency used indirectly; stable false positive for this package. ai

Versions (showing 8 of 8)

Version Deps Published
2.1.4 39 / 3
2.1.3 39 / 3
2.1.2 39 / 3
2.1.1 39 / 3
2.0.1 39 / 3
2.0.0 39 / 3
1.0.17 46 / 3
0.1.0 45 / 0

v2.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.