@sap-devx/inquirer-gui
Inquirer Graphical User Interface
5
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
shaharsrima.sirichsap-ospo-admin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Build bundle pattern; lodash used transitively or in config, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:vuetify | AI (phantom-deps): Vue UI framework referenced in build config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:strip-ansi | AI (phantom-deps): Utility used in build/config context; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@vscode-elements/elements | AI (phantom-deps): VS Code UI component dep referenced in config; stable false positive for this package. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 3.4.13 | 5 / 18 | |
| 3.4.11 | 5 / 18 | |
| 3.4.10 | 5 / 18 | |
| 3.4.9 | 5 / 18 | |
| 3.4.8 | 5 / 18 |
v3.4.9
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.4.8
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.