← Home

@univerjs/docs-thread-comment-ui

Univer thread comment plugin

84
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

jikkaiwbfsamengshukeji

Keywords

univerdocscommentthread-commentui

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@univerjs/icons AI (phantom-deps): Same-org monorepo dependency; transitively imported through other @univerjs packages. ai
dependencies unvetted-dep:@univerjs/core AI (dependencies): Sibling package in the Univer monorepo; unvetted status is a pipeline gap, not a risk. ai
dependencies unvetted-dep:@univerjs/docs AI (dependencies): Sibling package in the Univer monorepo; unvetted status is a pipeline gap, not a risk. ai
dependencies unvetted-dep:@univerjs/icons AI (dependencies): Sibling package in the Univer monorepo; unvetted status is a pipeline gap, not a risk. ai
dependencies unvetted-dep:@univerjs/ui AI (dependencies): Sibling package in the Univer monorepo; unvetted status is a pipeline gap, not a risk. ai
dependencies unvetted-dep:@univerjs/engine-render AI (dependencies): Sibling package in the Univer monorepo; unvetted status is a pipeline gap, not a risk. ai
dependencies unvetted-dep:@univerjs/thread-comment AI (dependencies): Sibling package in the Univer monorepo; unvetted status is a pipeline gap, not a risk. ai
dependencies unvetted-dep:@univerjs/thread-comment-ui AI (dependencies): Sibling package in the Univer monorepo; unvetted status is a pipeline gap, not a risk. ai
dependencies unvetted-dep:@univerjs/docs-ui AI (dependencies): Sibling package in the Univer monorepo; unvetted status is a pipeline gap, not a risk. ai

Versions (showing 84 of 84)

Version Deps Published
0.25.1 8 / 7
0.25.0 8 / 7
0.24.0 8 / 7
0.23.0 8 / 7
0.22.1 8 / 7
0.22.0 8 / 7
0.21.1 8 / 7
0.21.0 8 / 7
0.20.1 8 / 7
0.20.0 8 / 7
0.19.0 8 / 7
0.18.0 8 / 7
0.17.0 8 / 8
0.16.1 8 / 8
0.16.0 8 / 8
0.15.5 8 / 8
0.15.4 8 / 8
0.15.3 8 / 8
0.15.2 8 / 8
0.15.1 8 / 8
0.15.0 8 / 8
0.14.0 8 / 8
0.13.0 8 / 8
0.12.4 8 / 8
0.12.3 8 / 8
0.12.2 8 / 8
0.12.1 8 / 8
0.12.0 8 / 8
0.11.0 8 / 8
0.10.14 8 / 8
0.10.13 8 / 8
0.10.12 8 / 8
0.10.11 8 / 8
0.10.10 8 / 8
0.10.9 8 / 8
0.10.8 8 / 8
0.10.7 8 / 8
0.10.6 8 / 8
0.10.5 8 / 8
0.10.4 8 / 8
0.10.3 8 / 8
0.10.2 8 / 8
0.10.1 8 / 8
0.10.0 8 / 8
0.9.4 8 / 8
0.9.3 8 / 8
0.9.2 8 / 8
0.9.1 8 / 8
0.9.0 8 / 8
0.8.3 8 / 8
0.8.2 8 / 8
0.8.1 8 / 8
0.8.0 8 / 8
0.7.0 8 / 8
0.6.10 8 / 8
0.6.9 8 / 8
0.6.8 8 / 8
0.6.7 8 / 8
0.6.6 8 / 8
0.6.5 8 / 8
0.6.4 8 / 8
0.6.3 8 / 8
0.6.2 8 / 8
0.6.1 9 / 8
0.6.0 9 / 8
0.5.5 9 / 8
0.5.4 9 / 8
0.5.3 9 / 7
0.5.2 9 / 8
0.5.1 9 / 8
0.5.0 9 / 6
0.2.12 1 / 13
0.2.11 1 / 13
0.2.10 1 / 13
0.2.9 1 / 13
0.2.8 1 / 13
0.2.7 1 / 13
0.2.6 1 / 13
0.2.5 1 / 13
0.2.4 1 / 14
0.2.3 1 / 14
0.2.2 1 / 14
0.2.1 1 / 14
0.2.0 1 / 14

v0.25.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.