@trapar-waves/llm-template
A template for LLM development integrating AI tools, TypeScript, Zod validation, and development utilities like Vitest and Rslib.
12
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
muromi
Keywords
llmaitypescriptzodvitestviterslibprettiereslintdotenvpathe
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall runs 'husky' for git hooks setup; standard dev-tooling pattern, not malicious. | ai | |
| phantom-deps | phantom-dep:mdbox | AI (phantom-deps): mdbox is a declared runtime dependency; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:pathe | AI (phantom-deps): pathe is a declared runtime dependency; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): prettier is a declared runtime dependency; phantom-dep heuristic is a false positive here. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 1.2.0 | 7 / 10 | |
| 1.1.17 | 7 / 10 | |
| 1.1.0 | 7 / 10 | |
| 1.0.11 | 7 / 8 | |
| 1.0.10 | 7 / 8 | |
| 1.0.9 | 7 / 8 | |
| 1.0.8 | 7 / 8 | |
| 1.0.7 | 7 / 8 | |
| 1.0.6 | 7 / 8 | |
| 1.0.5 | 7 / 8 | |
| 1.0.4 | 7 / 8 | |
| 1.0.3 | 7 / 8 |
v1.0.3
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.