← Home

@revealui/core

21
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

revealui-org

Keywords

revealuicmsadmincollectionsrest-apiruntimerich-text

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher is confirmed by SLSA provenance attestation; consistent with CI/CD automation for this org. ai
phantom-deps phantom-dep:sharp AI (phantom-deps): Sharp is a well-known native image processing library commonly declared as a runtime dependency but used implicitly; this is expected behavior for this package. ai
typosquat typosquat.levenshtein:cors AI (typosquat): @revealui/core is a scoped CMS framework package; the Levenshtein match to 'cors' is a false positive with no plausible confusion vector. ai
phantom-deps phantom-dep:@lexical/clipboard AI (phantom-deps): @lexical/clipboard is a legitimate Meta/Lexical package; phantom-dep flag is a minor packaging concern, not a security risk. ai

Versions (showing 21 of 21)

Version Deps Published
0.12.2 23 / 9
0.12.1 23 / 9
0.12.0 24 / 9
0.11.1 24 / 9
0.11.0 24 / 9
0.10.2 25 / 9
0.10.1 25 / 9
0.10.0 25 / 9
0.9.0 26 / 9
0.8.0 26 / 9
0.7.0 25 / 9
0.6.0 25 / 9
0.5.6 25 / 9
0.5.5 25 / 9
0.5.4 25 / 9
0.5.3 25 / 9
0.5.2 25 / 9
0.5.0 25 / 9
0.3.0 25 / 9
0.2.1 23 / 9
0.2.0 24 / 9

v0.12.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.