@wg-npm/survey-response
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:quill | AI (dependencies): quill is a well-known rich text editor; its use in a survey-response component is expected and stable across versions. | ai | |
| phantom-deps | phantom-dep:quill | AI (phantom-deps): Quill is a runtime dependency referenced in rollup config; phantom-dep fires because it's not directly imported in source. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal scoped @wg-npm package; missing metadata is consistent across 683 versions, not a spam indicator. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable internal package; missing description is a persistent pattern, not a risk signal. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 1.78.4031900 | 1 / 38 | |
| 1.78.3051745 | 1 / 38 | |
| 1.78.511954 | 1 / 38 | |
| 1.78.511948 | 1 / 38 | |
| 1.78.511945 | 1 / 38 | |
| 1.78.511944 | 1 / 38 | |
| 1.78.511943 | 1 / 38 | |
| 1.78.511938 | 1 / 38 | |
| 1.78.511800 | 1 / 38 | |
| 1.78.222395 | 1 / 38 | |
| 1.77.2261800 | 1 / 38 | |
| 1.77.2131100 | 1 / 38 | |
| 1.77.2101755 | 1 / 38 | |
| 1.77.1131715 | 1 / 38 | |
| 1.77.113395 | 1 / 38 | |
| 1.77.112274 | 1 / 38 | |
| 1.77.101860 | 1 / 38 | |
| 1.77.96442 | 1 / 38 | |
| 0.5.740 | 1 / 38 |
v1.78.4031900
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.78.3051745
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.78.511954
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.78.511948
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.78.511945
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.78.511944
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.78.511938
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.78.511800
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.78.222395
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.2261800
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.2131100
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.2101755
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.1131715
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.113395
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.112274
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.101860
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.96442
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.740
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.