@plitzi/plitzi-ui
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Org-scoped UI library with real repo and deps; sparse metadata reflects early-stage project, not spam. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Missing description is a metadata gap, not a risk signal for this scoped package. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 1.6.18 | 28 / 51 | |
| 1.6.17 | 28 / 51 | |
| 1.6.16 | 28 / 51 | |
| 1.6.15 | 28 / 51 | |
| 1.6.14 | 28 / 51 | |
| 1.6.13 | 28 / 51 | |
| 1.6.12 | 28 / 51 | |
| 1.6.11 | 28 / 51 | |
| 1.6.10 | 28 / 51 | |
| 1.6.9 | 28 / 51 | |
| 1.6.8 | 28 / 51 | |
| 1.6.7 | 28 / 51 | |
| 1.6.6 | 28 / 51 | |
| 1.6.5 | 28 / 51 | |
| 1.6.4 | 28 / 51 | |
| 1.6.3 | 28 / 51 | |
| 1.6.2 | 28 / 51 |
v1.6.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.