@volue/wave-mcp
An MCP server that connects AI tools to the Wave Design System
13
Versions
UNLICENSED
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
fima1uzborg950it.management
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index-BFbS1JvB.js | AI (source-diff): Minified output from pkgroll --minify build step; content is readable bundled source with no malicious patterns. | ai | |
| provenance | no-provenance | AI (provenance): Internal org package; provenance absence is consistent across the @volue scope. | ai | |
| source-diff | obfuscated-file:dist/index-x3YulsFz.js | AI (source-diff): Minified bundle output from pkgroll --minify; content is design-system UI code, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-D5eBIUwA.js | AI (source-diff): Minified output from pkgroll --minify build step; content is design-system component code, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-LQNhghKN.js | AI (source-diff): Minified bundle produced by pkgroll --minify; content is clearly legitimate UI/design-system code from @volue org packages. | ai | |
| source-diff | obfuscated-file:dist/index-TBYX8fgI.js | AI (source-diff): Minified output from pkgroll --minify build step; content is design-system imports, not obfuscated malware. | ai | |
| phantom-deps | phantom-dep:@types/cors | AI (phantom-deps): Type-only dep; not imported at runtime, expected pattern. | ai | |
| phantom-deps | phantom-dep:@types/mdast | AI (phantom-deps): Type-only dep; not imported at runtime, expected pattern. | ai | |
| phantom-deps | phantom-dep:@types/express | AI (phantom-deps): Type-only dep; not imported at runtime, expected pattern. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Bundled by pkgroll; not imported directly but legitimately used in build output. | ai | |
| phantom-deps | phantom-dep:@volue/design-icons | AI (phantom-deps): Same-org dep; bundled by pkgroll for design system content. | ai | |
| phantom-deps | phantom-dep:@volue/design-colors | AI (phantom-deps): Same-org dep; bundled by pkgroll for design system content. | ai | |
| phantom-deps | phantom-dep:@volue/design-media-queries | AI (phantom-deps): Same-org dep; bundled by pkgroll for design system content. | ai | |
| phantom-deps | phantom-dep:@types/express-serve-static-core | AI (phantom-deps): Type-only dep; not imported at runtime, expected pattern. | ai | |
| phantom-deps | phantom-dep:cors | AI (phantom-deps): Bundled by pkgroll; legitimate runtime dep for HTTP transport. | ai | |
| phantom-deps | phantom-dep:express | AI (phantom-deps): Bundled by pkgroll; legitimate runtime dep for HTTP transport. | ai | |
| phantom-deps | phantom-dep:unified | AI (phantom-deps): Bundled by pkgroll; legitimate dep for markdown processing. | ai | |
| phantom-deps | phantom-dep:remark-parse | AI (phantom-deps): Bundled by pkgroll; legitimate dep for markdown processing. | ai | |
| phantom-deps | phantom-dep:xtend | AI (phantom-deps): Bundled by pkgroll; transitive utility dep. | ai |