@sap-devx/inquirer-gui
Inquirer Graphical User Interface
2
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
shaharsrima.sirichsap-ospo-admin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Build bundle pattern; lodash used transitively or in config, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:vuetify | AI (phantom-deps): Vue UI framework referenced in build config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:strip-ansi | AI (phantom-deps): Utility used in build/config context; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@vscode-elements/elements | AI (phantom-deps): VS Code UI component dep referenced in config; stable false positive for this package. | ai |
v3.4.11
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.