← Home

@tailor-cms/core-components

5
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

droguljicee_adminikovacundersc0perkusan00

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@tiptap/extension-underline AI (phantom-deps): Tiptap extensions referenced in config/peer context; stable pattern for this component library. ai
phantom-deps phantom-dep:@tiptap/extension-character-count AI (phantom-deps): Same as above; config-only reference pattern for this package. ai
phantom-deps phantom-dep:@tiptap/vue-3 AI (phantom-deps): Source-distributed library; @tiptap/vue-3 is a legitimate dependency for rich-text editor components. ai
phantom-deps phantom-dep:@tiptap/extensions AI (phantom-deps): Source-distributed library; @tiptap/extensions is a legitimate dependency for rich-text editor components. ai
phantom-deps phantom-dep:@tiptap/starter-kit AI (phantom-deps): Source-distributed library; @tiptap/starter-kit is a legitimate dependency for rich-text editor components. ai
phantom-deps phantom-dep:@tailor-cms/interfaces AI (phantom-deps): Same-org scope package explicitly listed in bundleDependencies; phantom detection is a false positive here. ai
phantom-deps phantom-dep:@tiptap/pm AI (phantom-deps): Source-distributed Vue component library; tiptap deps may be re-exported or used indirectly. Legitimate dependency for a rich-text editor component. ai
phantom-deps phantom-dep:@tiptap/extension-subscript AI (phantom-deps): Source-distributed library; tiptap extension is a legitimate dependency for rich-text editor components. ai
phantom-deps phantom-dep:@tiptap/extension-superscript AI (phantom-deps): Source-distributed library; tiptap extension is a legitimate dependency for rich-text editor components. ai
phantom-deps phantom-dep:chart.js AI (phantom-deps): Source-distributed library; chart.js is a legitimate charting dependency used indirectly via vue-chartjs. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Source-distributed library; @vueuse/core is a standard Vue utility library used indirectly in component composition. ai
phantom-deps phantom-dep:chartjs-plugin-datalabels AI (phantom-deps): Source-distributed library; chartjs-plugin-datalabels is a legitimate charting plugin used indirectly. ai
phantom-deps phantom-dep:vue-chartjs AI (phantom-deps): Source-distributed library; vue-chartjs is a legitimate charting dependency used indirectly in component composition. ai

Versions (showing 5 of 5)

Version Deps Published
1.2.4 11 / 2
1.2.1 9 / 2
1.1.2 9 / 2
1.1.1 9 / 2
1.0.37 9 / 1

v1.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.