← Home

@rnacanvas/app-object

The RNAcanvas app object

51
Versions
GPL-3.0-only
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

pzhaojohnson

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:uuid AI (phantom-deps): Webpack-bundled package; declared deps may not appear as direct imports in source. Consistent with package build pattern. ai
phantom-deps phantom-dep:@rnacanvas/start-page AI (phantom-deps): Same-org dep in a webpack-bundled package; phantom-dep heuristic is a stable false positive here. ai
dependencies unvetted-dep:@rnacanvas/buttons AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/draw AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/toolbar AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/draw.svg AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/forms.new AI (dependencies): Same-org dep from established RNAcanvas monorepo; newly added but consistent with org pattern. ai
dependencies unvetted-dep:@rnacanvas/base-pairs AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/forms.edit AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/forms.find AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/forms.open AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/scrollbars AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/forms.about AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/forms.export AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/forms.layout AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/draw.interact AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/drop-interface AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/draw.bases.bonds AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/draw.svg.interact AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/draw.svg.highlight AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
dependencies unvetted-dep:@rnacanvas/ct AI (dependencies): Same-org dep from established RNAcanvas monorepo; stable pattern across all versions. ai
phantom-deps phantom-dep:@rnacanvas/value-check AI (phantom-deps): Same-org dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@rnacanvas/parse AI (phantom-deps): Same-org dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@rnacanvas/ct AI (phantom-deps): Same-org dep; phantom-dep heuristic false positive for this monorepo-style package. ai
phantom-deps phantom-dep:@rnacanvas/base-pairs AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai
phantom-deps phantom-dep:@rnacanvas/forms.edit AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai
phantom-deps phantom-dep:@rnacanvas/forms.find AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai
phantom-deps phantom-dep:@rnacanvas/forms.open AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai
phantom-deps phantom-dep:@rnacanvas/forms.about AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai
phantom-deps phantom-dep:@rnacanvas/buttons AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai
phantom-deps phantom-dep:@rnacanvas/paste-interface AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai
phantom-deps phantom-dep:@rnacanvas/draw.bases.bonds AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai
phantom-deps phantom-dep:@rnacanvas/draw.svg.interact AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai
phantom-deps phantom-dep:jquery AI (phantom-deps): jquery is a declared runtime dep; phantom-dep false positive likely due to indirect/bundled usage. ai
provenance no-provenance AI (provenance): Publisher consistently publishes without provenance; no other risk signals present. ai
phantom-deps phantom-dep:@rnacanvas/drop-interface AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai
phantom-deps phantom-dep:@rnacanvas/toolbar AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai
phantom-deps phantom-dep:@rnacanvas/draw.svg AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for this monorepo-style split. ai

Versions (showing 51 of 116)

View all versions
Version Deps Published
17.11.3 26 / 13
17.11.2 26 / 13
17.11.1 26 / 13
17.11.0 26 / 13
17.10.3 26 / 13
17.10.2 26 / 13
17.10.1 26 / 13
17.10.0 26 / 13
17.9.0 26 / 13
17.8.8 26 / 13
17.8.7 26 / 13
17.8.6 26 / 13
17.8.5 26 / 13
17.8.4 26 / 13
17.8.3 26 / 13
17.8.2 26 / 13
17.8.1 26 / 13
17.8.0 26 / 13
17.7.0 26 / 13
17.6.4 26 / 13
17.6.3 26 / 13
17.6.2 26 / 13
17.6.1 26 / 13
17.6.0 26 / 13
17.5.0 26 / 13
17.4.0 26 / 13
17.3.1 26 / 13
17.3.0 26 / 13
17.2.6 26 / 13
17.2.5 26 / 13
17.2.4 26 / 13
17.2.3 26 / 13
17.2.2 26 / 13
17.2.1 26 / 13
17.2.0 26 / 13
17.1.0 24 / 13
17.0.0 24 / 13
16.11.4 24 / 13
16.11.3 24 / 13
16.11.2 24 / 13
16.11.1 24 / 13
16.11.0 24 / 13
16.10.0 23 / 13
16.9.0 23 / 13
16.8.0 23 / 13
16.7.0 23 / 13
16.6.0 23 / 13
16.5.1 23 / 13
16.5.0 23 / 13
16.4.2 20 / 13
16.4.1 20 / 13

v17.11.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.11.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.11.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.11.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.10.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.10.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.10.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.10.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.9.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.8.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.8.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.8.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.8.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.8.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.8.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.8.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.8.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.8.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.6.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.6.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.6.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.2.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.2.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.2.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.2.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.11.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.11.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.11.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.11.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.11.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.10.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.9.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.8.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v16.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.4.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v16.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.