@quilted/quilt
10
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
lemonmade
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Package migrated to GitHub Actions CI publishing with SLSA attestation; lemonmade repo ownership unchanged. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established umbrella package; missing description is a stable characteristic, not a malice indicator. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI pipeline naturally produces rapid successive publishes across the monorepo. | ai | |
| phantom-deps | phantom-dep:@quilted/async | AI (phantom-deps): Re-exported sibling; phantom-dep heuristic is a stable false positive for this monorepo umbrella package. | ai | |
| dependencies | unvetted-dep:@quilted/assets | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/signals | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/react-dom | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/preact-async | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/preact-router | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/preact-context | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/preact-graphql | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/preact-signals | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/preact-testing | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/preact-workers | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/preact-localize | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/preact-performance | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/preact-browser | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/hono | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/async | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@quilted/react | AI (dependencies): Same-org monorepo sibling; not a third-party risk. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Umbrella/facade package; empty main entry is intentional re-export pattern for this monorepo. | ai | |
| phantom-deps | phantom-dep:@quilted/react-dom | AI (phantom-deps): Same-org first-party dep; phantom detection is a false positive for monorepo re-export packages. | ai | |
| phantom-deps | phantom-dep:@quilted/signals | AI (phantom-deps): Same-org first-party dep; phantom detection is a false positive for monorepo re-export packages. | ai | |
| phantom-deps | phantom-dep:@quilted/react | AI (phantom-deps): Same-org first-party dep; phantom detection is a false positive for monorepo re-export packages. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 0.10.2 | 21 / 4 | |
| 0.10.1 | 21 / 4 | |
| 0.9.8 | 21 / 4 | |
| 0.9.7 | 21 / 4 | |
| 0.9.6 | 21 / 4 | |
| 0.9.5 | 21 / 4 | |
| 0.9.4 | 21 / 4 | |
| 0.9.2 | 21 / 4 | |
| 0.9.1 | 21 / 4 | |
| 0.9.0 | 21 / 4 |
v0.10.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.