← Home

@solid-devtools/shared

1
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

thetarnav.

Keywords

soliddevtools

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@solid-primitives/refs AI (dependencies): @solid-primitives/refs is a legitimate SolidJS community primitive; stable dependency for this package. ai
dependencies unvetted-dep:@solid-primitives/media AI (dependencies): @solid-primitives/media is a legitimate SolidJS community primitive; stable dependency for this package. ai
dependencies unvetted-dep:@solid-primitives/styles AI (dependencies): @solid-primitives/styles is a legitimate SolidJS community primitive; stable dependency for this package. ai
dependencies unvetted-dep:@solid-primitives/rootless AI (dependencies): @solid-primitives/rootless is a legitimate SolidJS community primitive; stable dependency for this package. ai
dependencies unvetted-dep:@solid-primitives/scheduled AI (dependencies): @solid-primitives/scheduled is a legitimate SolidJS community primitive; stable dependency for this package. ai
dependencies unvetted-dep:@solid-primitives/static-store AI (dependencies): @solid-primitives/static-store is a legitimate SolidJS community primitive; stable dependency for this package. ai
dependencies unvetted-dep:@solid-primitives/event-listener AI (dependencies): @solid-primitives/event-listener is a legitimate SolidJS community primitive; stable dependency for this package. ai
phantom-deps phantom-dep:@solid-primitives/refs AI (phantom-deps): Referenced in build/config files in monorepo context; not a phantom dep concern for this package. ai
phantom-deps phantom-dep:@solid-primitives/styles AI (phantom-deps): Referenced in build/config files in monorepo context; not a phantom dep concern for this package. ai
phantom-deps phantom-dep:@solid-primitives/scheduled AI (phantom-deps): Referenced in build/config files in monorepo context; not a phantom dep concern for this package. ai
phantom-deps phantom-dep:@solid-primitives/static-store AI (phantom-deps): Referenced in build/config files in monorepo context; not a phantom dep concern for this package. ai

Versions (showing 1 of 1)

Version Deps Published
0.20.0 9 / 0

v0.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.