← Home

@vitessce/spatial-accelerated

18
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

keller-mark

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata no-description AI (npm-metadata): Scoped package in established monorepo; missing description is stable pattern. ai
provenance no-provenance AI (provenance): Only ~12% of npm packages have provenance; not a disqualifier for this context. ai
bogus-package bogus-package AI (bogus-package): Monorepo package with coordinated versioning; missing description and inflated semver are expected patterns. ai
dependencies unvetted-dep:short-number AI (dependencies): Legitimate number-formatting utility; stable dependency in this monorepo package. ai
dependencies unvetted-dep:@react-three/xr AI (dependencies): Well-known React Three Fiber XR extension; expected dep for a spatial/3D visualization package. ai
phantom-deps phantom-dep:@vitessce/styles AI (phantom-deps): Same-org monorepo package; phantom-dep heuristic unreliable for monorepo internal deps. ai
phantom-deps phantom-dep:@vitessce/gl AI (phantom-deps): Same-org monorepo sibling; phantom-dep is a false positive here. ai
phantom-deps phantom-dep:short-number AI (phantom-deps): Monorepo component; deps declared for bundling, not direct import. ai
phantom-deps phantom-dep:@react-three/xr AI (phantom-deps): Monorepo component; deps declared for bundling, not direct import. ai
phantom-deps phantom-dep:@vitessce/utils AI (phantom-deps): Same-org monorepo sibling; phantom-dep is a false positive here. ai
phantom-deps phantom-dep:plur AI (phantom-deps): Monorepo component; deps declared for bundling, not direct import. ai
phantom-deps phantom-dep:@vitessce/legend AI (phantom-deps): Same-org monorepo sibling; phantom-dep is a false positive here. ai
phantom-deps phantom-dep:@vitessce/tooltip AI (phantom-deps): Same-org monorepo sibling; phantom-dep is a false positive here. ai
phantom-deps phantom-dep:@vitessce/sets-utils AI (phantom-deps): Same-org monorepo sibling; phantom-dep is a false positive here. ai
phantom-deps phantom-dep:@vitessce/spatial-utils AI (phantom-deps): Same-org monorepo sibling; phantom-dep is a false positive here. ai
phantom-deps phantom-dep:@vitessce/vit-s AI (phantom-deps): Same-org monorepo sibling; phantom-dep is a false positive here. ai
phantom-deps phantom-dep:mathjs AI (phantom-deps): Monorepo component; deps declared for bundling, not direct import. ai
phantom-deps phantom-dep:math.gl AI (phantom-deps): Monorepo component; deps declared for bundling, not direct import. ai
phantom-deps phantom-dep:zarrita AI (phantom-deps): Monorepo component; deps declared for bundling, not direct import. ai
phantom-deps phantom-dep:d3-array AI (phantom-deps): Monorepo component; deps declared for bundling, not direct import. ai
phantom-deps phantom-dep:internmap AI (phantom-deps): Monorepo component; deps declared for bundling, not direct import. ai

Versions (showing 18 of 18)

Version Deps Published
3.9.11 22 / 5
3.9.10 22 / 5
3.9.9 22 / 5
3.9.8 22 / 5
3.9.7 22 / 5
3.9.6 22 / 5
3.9.5 22 / 5
3.8.10 22 / 5
3.8.9 22 / 5
3.8.8 22 / 5
3.8.7 22 / 5
3.8.6 22 / 5
3.8.5 22 / 5
3.8.4 22 / 5
3.8.3 22 / 5
3.8.2 22 / 5
3.8.1 22 / 5
3.8.0 22 / 5

v3.9.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.8.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.8.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.8.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.8.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.8.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.8.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.8.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.