← Home

@stencil/vue-output-target

26
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ionicjsgm-osvmfognbmjohnny.jenkinsstencil-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Ionic/StencilJS org transitioned to GitHub Actions CI publishing with SLSA attestation; stable for this package. ai
publish-pattern dormant-publish AI (publish-pattern): Active development continued on GitHub; gap reflects npm release cadence, not abandonment or takeover. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers gm-os and johnny.jenkins are consistent with Ionic org team expansion; SLSA provenance confirms CI-controlled publish. ai
provenance slsa-provenance AI (provenance): Official Ionic/StencilJS CI pipeline; SLSA attestation is stable for this package. ai

Versions (showing 26 of 26)

Version Deps Published
0.14.1 0 / 14
0.14.0 1 / 13
0.13.2 0 / 12
0.13.1 0 / 12
0.13.0 0 / 12
0.12.2 0 / 12
0.12.1 0 / 12
0.12.0 0 / 9
0.11.8 0 / 9
0.10.8 0 / 9
0.10.7 0 / 8
0.10.6 0 / 7
0.10.5 0 / 7
0.10.4 0 / 7
0.10.3 0 / 7
0.10.2 0 / 7
0.10.1 0 / 7
0.10.0 0 / 7
0.9.6 0 / 6
0.9.5 0 / 6
0.9.4 0 / 6
0.9.3 0 / 6
0.9.2 0 / 6
0.9.1 0 / 7
0.9.0 0 / 7
0.8.9 0 / 0

v0.14.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ionicjs → stencil-bot (on 2025-03-05, known maintainer) provenance

This version was published by a different npm account (stencil-bot) than the most recent previously approved version (ionicjs) on 2025-03-05, but stencil-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.9.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ionicjs → stencil-bot (on 2025-02-25, known maintainer) provenance

This version was published by a different npm account (stencil-bot) than the most recent previously approved version (ionicjs) on 2025-02-25, but stencil-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.9.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.