@sanity/import
14
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
sanity-svc.npmsanity-io
Keywords
sanitycmsheadlessrealtimecontentimportndjson
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; missing gitHead reflects CI pipeline change, not a supply chain risk for this org package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Sanity.io org-level maintainer rotation; published by org service account with strong provenance attestation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Sanity.io org-level maintainer rotation; consistent with internal team changes at an established org. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-help | AI (phantom-deps): @oclif/plugin-help is declared as an oclif plugin in config, not directly imported in code — stable false positive for this package. | ai |