← Home

@univerjs/core

8
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

jikkaiwbfsamengshukeji

Keywords

univeroffice-sdkcoreruntimefacade

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:dayjs AI (phantom-deps): Likely used in bundled/minified output; benign like the already-accepted nanoid/numeral phantom deps. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Minified bundle output using Reflect.get for property access, not evasive obfuscation. ai
phantom-deps phantom-dep:numfmt AI (phantom-deps): Used via config, stable pattern for this monorepo package. ai
phantom-deps phantom-dep:numeral AI (phantom-deps): Used via config, stable pattern for this monorepo package. ai
phantom-deps phantom-dep:kdbush AI (phantom-deps): kdbush is a declared dependency used in bundled output; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:nanoid AI (phantom-deps): nanoid is a declared dependency used in bundled output; phantom-dep heuristic false positive for this package. ai
typosquat typosquat.levenshtein:cors AI (typosquat): @univerjs/core is the core of the Univer framework, not a typo of cors; scoped package name makes this a stable false positive. ai

Versions (showing 8 of 108)

Version Deps Published
0.1.8 3 / 8
0.1.7 4 / 7
0.1.6 4 / 7
0.1.5 4 / 7
0.1.4 3 / 8
0.1.3 3 / 8
0.1.2 3 / 7
0.1.1 3 / 7

v0.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.