← Home

@slidev/client

17
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

antfu_kerman

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:prettier AI (phantom-deps): Optional formatting dep loaded dynamically; stable false positive for this package. ai
phantom-deps phantom-dep:@unocss/reset AI (phantom-deps): CSS reset loaded via config/build pipeline, not direct import; stable false positive. ai
phantom-deps phantom-dep:shiki-magic-move AI (phantom-deps): Lazy-loaded feature dep; phantom-dep heuristic is a false positive for this package. ai
phantom-deps phantom-dep:katex AI (phantom-deps): Optional feature dep loaded dynamically; stable false positive. ai
phantom-deps phantom-dep:fuse.js AI (phantom-deps): Optional search feature dep; stable false positive. ai
phantom-deps phantom-dep:nanotar AI (phantom-deps): Optional export feature dep; stable false positive. ai
semgrep semgrep:new-function-constructor AI (semgrep): Intentional code-runner sandbox for executing user slide code; stable pattern for this package. ai
phantom-deps phantom-dep:@iconify-json/ph AI (phantom-deps): Icon data package used via UnoCSS preset; stable false positive. ai
phantom-deps phantom-dep:@iconify-json/carbon AI (phantom-deps): Icon data package used via UnoCSS preset; stable false positive. ai
phantom-deps phantom-dep:@iconify-json/svg-spinners AI (phantom-deps): Icon data package used via UnoCSS preset; stable false positive. ai
phantom-deps phantom-dep:pptxgenjs AI (phantom-deps): Optional PPTX export dep; stable false positive. ai
bogus-package bogus-package AI (bogus-package): Slidev client is a well-known monorepo package; sparse README/keywords are expected for internal workspace packages. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): Declared as optional/peer-style dep used via config; stable false positive for this package. ai

Versions (showing 17 of 17)

Version Deps Published
52.16.0 38 / 1
52.15.2 38 / 1
52.15.1 38 / 1
52.15.0 38 / 1
52.14.0 37 / 1
52.11.5 35 / 1
52.11.4 35 / 1
52.6.0 35 / 1
52.5.0 35 / 1
52.4.0 35 / 1
52.3.0 35 / 1
52.2.5 35 / 1
52.2.4 35 / 1
52.2.3 35 / 1
52.1.0 35 / 1
52.0.1 35 / 1
52.0.0 35 / 1

v52.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.15.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.15.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.14.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.11.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.11.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.2.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v52.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.