@steedos-widgets/amis-object
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): Build-tool dependency used in rollup-plugin-postcss config, not direct import. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): Build-tool dependency invoked in build:tailwind script, not direct import. | ai | |
| phantom-deps | phantom-dep:autoprefixer | AI (phantom-deps): Build-tool dependency used in postcss config, not direct import. | ai |
Versions (showing 51 of 55)
| Version | Deps | Published |
|---|---|---|
| 6.10.53 | 0 / 40 | |
| 6.10.51 | 0 / 40 | |
| 6.10.49 | 0 / 40 | |
| 6.10.48 | 0 / 40 | |
| 6.10.47 | 0 / 40 | |
| 6.10.46 | 0 / 40 | |
| 6.10.45 | 0 / 40 | |
| 6.10.44 | 0 / 40 | |
| 6.10.43 | 0 / 40 | |
| 6.10.42 | 0 / 40 | |
| 6.10.41 | 0 / 40 | |
| 6.10.40 | 0 / 40 | |
| 6.10.39 | 0 / 40 | |
| 6.10.38 | 0 / 40 | |
| 6.10.37 | 0 / 40 | |
| 6.10.36 | 0 / 40 | |
| 6.10.35 | 0 / 40 | |
| 6.10.34 | 0 / 40 | |
| 6.10.33 | 5 / 36 | |
| 6.10.32 | 5 / 36 | |
| 6.10.31 | 5 / 36 | |
| 6.10.30 | 5 / 36 | |
| 6.10.29 | 5 / 36 | |
| 6.10.28 | 5 / 36 | |
| 6.10.27 | 5 / 36 | |
| 6.10.26 | 5 / 36 | |
| 6.10.25 | 5 / 36 | |
| 6.10.24 | 5 / 36 | |
| 6.10.23 | 5 / 36 | |
| 6.10.22 | 5 / 36 | |
| 6.10.21 | 5 / 36 | |
| 6.10.20 | 5 / 36 | |
| 6.10.19 | 4 / 36 | |
| 6.10.18 | 4 / 36 | |
| 6.10.17 | 4 / 36 | |
| 6.10.16 | 4 / 36 | |
| 6.10.15 | 4 / 36 | |
| 6.10.14 | 4 / 36 | |
| 6.10.13 | 4 / 36 | |
| 6.10.12 | 4 / 36 | |
| 6.10.11 | 4 / 36 | |
| 6.10.10 | 4 / 36 | |
| 6.10.9 | 4 / 36 | |
| 6.10.8 | 4 / 36 | |
| 6.10.7 | 4 / 36 | |
| 6.10.6 | 4 / 36 | |
| 6.10.5 | 4 / 36 | |
| 6.10.4 | 4 / 36 | |
| 6.10.3 | 4 / 36 | |
| 6.10.1 | 4 / 36 | |
| 6.3.17 | 4 / 36 |
v6.10.53
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (steedos-baozhoutao) than the most recent previously approved version (steedos-zhuangjianguo) on 2026-05-27, but steedos-baozhoutao is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.10.51
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.49
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.48
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.47
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.46
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.45
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.44
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.10.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.3.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.