@vef-framework-react/dev
Dev tools for VEF framework
24
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
coldsmirk
Keywords
vefframeworkreactdev
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): Adds maintainer's own tooling configs, not third-party attack-surface deps. | ai | |
| dependencies | unvetted-dep:@coldsmirk/eslint-config | AI (dependencies): Maintainer's own scoped config package, consistent with prior eslint-config usage. | ai | |
| dependencies | unvetted-dep:@coldsmirk/stylelint-config | AI (dependencies): Maintainer's own scoped config package, replacing prior stylelint deps. | ai | |
| dependencies | unvetted-dep:@coldsmirk/commitlint-config | AI (dependencies): Maintainer's own scoped config package, replacing prior commitlint deps. | ai | |
| source-diff | obfuscated-file:dist/cjs/code-generation/dictionary/core.cjs | AI (source-diff): File is minified CJS bundle output (rolldown/tsup), not obfuscated; content is benign dictionary key code generation logic. | ai | |
| phantom-deps | phantom-dep:prompts | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Convention-loaded Babel plugin; stable for framework packages. | ai | |
| phantom-deps | phantom-dep:sass-embedded | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:@babel/traverse | AI (phantom-deps): Convention-loaded Babel plugin; stable for framework packages. | ai | |
| phantom-deps | phantom-dep:@emotion/babel-plugin | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/utils | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:babel-plugin-react-compiler | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:@commitlint/config-conventional | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:@svgr/plugin-svgo | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:ora | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:execa | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Config-file reference in dev framework; stable pattern. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): Scoped package @vef-framework-react/dev; levenshtein match to ajv is a clear false positive. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 2.7.0 | 34 / 10 | |
| 2.6.0 | 34 / 10 | |
| 2.5.0 | 34 / 10 | |
| 2.4.4 | 54 / 15 | |
| 2.4.3 | 54 / 15 | |
| 2.4.2 | 54 / 15 | |
| 2.4.1 | 54 / 15 | |
| 2.4.0 | 53 / 16 | |
| 2.3.0 | 53 / 16 | |
| 2.2.2 | 52 / 16 | |
| 2.2.1 | 52 / 16 | |
| 2.2.0 | 52 / 16 | |
| 2.1.12 | 52 / 16 | |
| 2.1.11 | 52 / 16 | |
| 2.1.9 | 52 / 16 | |
| 2.1.8 | 49 / 19 | |
| 2.1.7 | 49 / 19 | |
| 2.1.6 | 49 / 17 | |
| 2.1.5 | 49 / 17 | |
| 2.1.4 | 49 / 17 | |
| 2.1.3 | 49 / 17 | |
| 2.1.2 | 49 / 17 | |
| 2.1.1 | 49 / 17 | |
| 2.1.0 | 49 / 17 |
v2.7.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.