← Home

@storecraft/dashboard

Storecraft Official Dashboard

3
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

hendrixstring

Keywords

commercedashboardreactstorecraft

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Established storecraft org package; lack of provenance is common and not a risk signal here. ai
phantom-deps phantom-dep:js-base64 AI (phantom-deps): Same bundled library pattern; stable false positive for this package. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Peer dep used via Vite build; not directly imported in source. ai
phantom-deps phantom-dep:react-icons AI (phantom-deps): Bundled UI library; phantom-dep is a false positive for this build setup. ai
phantom-deps phantom-dep:tailwindcss AI (phantom-deps): CSS tooling used via Vite plugin, not direct JS import. ai
phantom-deps phantom-dep:monaco-editor AI (phantom-deps): Loaded via @monaco-editor/react wrapper; phantom-dep is a false positive. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Vite-bundled library; deps referenced in config/build artifacts, not direct imports. ai
phantom-deps phantom-dep:react-image-crop AI (phantom-deps): Bundled dep; stable false positive for this Vite library package. ai
phantom-deps phantom-dep:@tailwindcss/vite AI (phantom-deps): Vite plugin; used in config not directly imported in source. ai
phantom-deps phantom-dep:react-drag-drop-container AI (phantom-deps): Bundled dep; stable false positive for this Vite library package. ai
phantom-deps phantom-dep:react-markdown-editor-lite AI (phantom-deps): Bundled dep; stable false positive for this Vite library package. ai
phantom-deps phantom-dep:react-inspector AI (phantom-deps): Bundled dep; stable false positive for this Vite library package. ai

Versions (showing 3 of 3)

Version Deps Published
1.4.2 19 / 18
1.3.0 19 / 18
1.2.5 19 / 18

v1.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.