← Home

@volar/vue-code-gen

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

johnsoncodehk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Signals reflect compiled build output with minimal metadata, not malware. Legitimate GitHub repo, proper license. ai
phantom-deps phantom-dep:@volar/source-map AI (phantom-deps): Same-org dependency used indirectly through build output; expected for monorepo packages. ai
phantom-deps phantom-dep:@vue/compiler-dom AI (phantom-deps): Vue framework package loaded by convention in compiler tooling; expected phantom dep pattern. ai
phantom-deps phantom-dep:@vue/compiler-core AI (phantom-deps): Vue framework package loaded by convention in compiler tooling; expected phantom dep pattern. ai
source-diff source-size-dropped AI (source-diff): Source files excluded from npm package per files field; compiled output only. Standard practice. ai
phantom-deps phantom-dep:@vue/shared AI (phantom-deps): Vue framework package loaded by convention in compiler tooling; expected phantom dep pattern. ai
phantom-deps phantom-dep:@volar/code-gen AI (phantom-deps): Same-org dependency used indirectly through build output; expected for monorepo packages. ai
source-diff large-new-source-files AI (source-diff): Volar is a Vue language tooling package; large generated JS files in out/ are expected build artifacts for a code generation library. This pattern is stable across versions. ai
provenance no-provenance AI (provenance): Older package predating widespread Sigstore adoption; trusted publisher with 2533 approved packages. Absence of provenance is not a risk signal here. ai
dependencies unvetted-dep:@vue/compiler-core AI (dependencies): @vue/compiler-core is an official Vue.js core package, expected and appropriate for a Vue code generation library. ai
npm-metadata no-description AI (npm-metadata): Monorepo sub-package from the established Volar ecosystem; missing description is a stable cosmetic omission, not a malicious signal. ai

Versions (showing 51 of 77)

View all versions
Version Deps Published
0.39.5 5 / 1
0.39.4 5 / 1
0.39.3 5 / 1
0.39.2 5 / 1
0.39.0 5 / 1
0.38.9 5 / 1
0.38.8 5 / 1
0.38.7 5 / 1
0.38.5 5 / 1
0.38.4 5 / 1
0.38.3 5 / 1
0.38.2 5 / 1
0.38.1 5 / 1
0.38.0 5 / 1
0.37.9 5 / 1
0.37.8 5 / 1
0.37.7 5 / 1
0.37.5 5 / 1
0.37.4 5 / 1
0.37.3 5 / 1
0.37.2 5 / 1
0.37.1 5 / 1
0.37.0 5 / 1
0.36.1 5 / 1
0.36.0 5 / 1
0.35.2 5 / 1
0.35.1 5 / 1
0.35.0 5 / 1
0.34.17 5 / 1
0.34.16 5 / 1
0.34.15 5 / 1
0.34.13 5 / 1
0.34.12 5 / 1
0.34.11 5 / 1
0.34.10 5 / 1
0.34.9 5 / 1
0.34.8 5 / 1
0.34.7 5 / 1
0.34.6 5 / 1
0.34.5 5 / 1
0.34.4 5 / 1
0.34.3 5 / 1
0.34.2 5 / 1
0.34.1 5 / 1
0.34.0 5 / 1
0.33.9 5 / 1
0.33.7 5 / 1
0.33.6 5 / 1
0.33.5 5 / 1
0.33.4 5 / 1
0.33.3 5 / 1

v0.39.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.39.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.39.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.38.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.38.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.38.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.38.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.38.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.38.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.38.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.37.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.36.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.36.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.35.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.35.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.33.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.33.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.33.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.33.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.