← Home

@tailor-cms/ce-file-edit

Tailor CMS file authoring component

2
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

droguljicee_adminikovacundersc0perkusan00

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Package is a legitimate @tailor-cms org component; sparse metadata (no repo URL, no keywords) is a documentation gap, not a spam/malware indicator. Author field links to the tailor-cms GitHub org. ai
phantom-deps phantom-dep:lodash-es AI (phantom-deps): lodash-es is a legitimate utility library declared as a runtime dep; phantom detection likely reflects indirect usage via build output or re-exports. ai
phantom-deps phantom-dep:@tailor-cms/core-components AI (phantom-deps): Same org scope dependency; phantom detection reflects build-time or indirect usage patterns common in monorepo component packages. ai

Versions (showing 2 of 2)

Version Deps Published
0.1.0 2 / 7
0.0.1 2 / 7

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.