← Home

@visactor/vchart-extension

14
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

liufangfangvisactorownerxuanhunzamhownchensiji.0517youngwindspurpose233ssfxzlixuefei.1313ray_sunxiaoluohesimaqxile611da730zhouxinyu66888zexian_chen

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@visactor/vlayouts AI (dependencies): Same-org @visactor package; consistent with the broader VChart ecosystem dependency pattern. ai
provenance no-provenance AI (provenance): Large established org package; lack of provenance is common and not a risk signal here. ai
bogus-package bogus-package AI (bogus-package): Extension wrapper package in a large org monorepo; tiny payload and missing metadata are expected for this type of package. ai
phantom-deps phantom-dep:@visactor/vchart AI (phantom-deps): Same-org peer dependency pattern; stable for this package. ai
phantom-deps phantom-dep:@visactor/vutils AI (phantom-deps): Same-org peer dependency pattern; stable for this package. ai
phantom-deps phantom-dep:@visactor/vrender-core AI (phantom-deps): Same-org peer dependency pattern; stable for this package. ai
phantom-deps phantom-dep:@visactor/vlayouts AI (phantom-deps): Same-org transitive dep; stable false positive for this package. ai
phantom-deps phantom-dep:@visactor/vrender-kits AI (phantom-deps): Same-org transitive dep; stable false positive for this package. ai
phantom-deps phantom-dep:@visactor/vrender-animate AI (phantom-deps): Same-org transitive dep; stable false positive for this package. ai
phantom-deps phantom-dep:@visactor/vrender-components AI (phantom-deps): Same-org transitive dep; stable false positive for this package. ai
phantom-deps phantom-dep:@visactor/vdataset AI (phantom-deps): Same-org transitive dep; not directly imported but legitimately declared for peer resolution. ai

Versions (showing 14 of 14)

Version Deps Published
2.0.22 8 / 24
2.0.21 8 / 24
2.0.20 8 / 24
2.0.11 8 / 24
2.0.6 8 / 24
2.0.2 8 / 24
2.0.1 8 / 24
2.0.0 8 / 24
1.13.27 8 / 24
1.13.26 8 / 24
1.13.25 8 / 24
1.13.24 8 / 24
1.13.23 8 / 24
1.13.22 8 / 24

v2.0.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.13.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.13.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.13.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.13.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.13.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.