@skeletonlabs/skeleton-svelte
The Svelte package for Skeleton.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@internationalized/date | AI (phantom-deps): Used transitively via @zag-js/date-picker; Svelte component libraries often don't directly import all declared deps. | ai | |
| phantom-deps | phantom-dep:@skeletonlabs/skeleton-common | AI (phantom-deps): Same-org sibling package; likely re-exported or used in build artifacts rather than direct imports. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 4.15.2 | 29 / 0 | |
| 4.15.1 | 29 / 0 | |
| 4.15.0 | 29 / 0 | |
| 4.13.0 | 29 / 0 | |
| 4.12.0 | 29 / 0 | |
| 4.10.0 | 29 / 0 | |
| 4.7.4 | 28 / 0 | |
| 4.7.3 | 28 / 0 | |
| 4.7.1 | 28 / 0 | |
| 4.7.0 | 28 / 0 | |
| 4.5.2 | 26 / 0 | |
| 4.5.0 | 26 / 12 | |
| 4.4.1 | 26 / 12 | |
| 4.3.3 | 25 / 12 | |
| 4.3.0 | 25 / 12 | |
| 4.2.3 | 25 / 12 | |
| 4.1.0 | 24 / 12 |
v4.15.2
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.15.1
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.15.0
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.13.0
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.0
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.10.0
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.7.4
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.7.3
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.7.1
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.7.0
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.5.2
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.5.0
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.4.1
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.3
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.0
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.3
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.1.0
2 findingsMaintainer email '[email protected]' uses domain 'skeletonlabs.dev' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.