← Home

@yiitap/vue

A WYSIWYG rich-text block-based editor built on top of tiptap.

21
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

mekery

Keywords

editorwysiwygblocknotionyiitaptiptaptypescriptvue

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@yiitap/vue AI (phantom-deps): Self-reference in monorepo dep list, benign. ai
dependencies unvetted-dep:@yiitap/extension-unique-id AI (dependencies): First-party sibling package from same publisher/monorepo. ai
dependencies unvetted-dep:@yiitap/extension-trailing-node AI (dependencies): First-party sibling package from same publisher/monorepo. ai
source-diff large-new-source-files AI (source-diff): Expected growth from adding first-party extension modules. ai
publish-pattern new-deps-added AI (publish-pattern): All added deps are first-party @tiptap/@yiitap editor extensions matching stated function. ai
dependencies unvetted-dep:@yiitap/extension-focus AI (dependencies): First-party org package split out from monolith. ai
phantom-deps phantom-dep:@floating-ui/dom AI (phantom-deps): Used via config/build tooling, not a direct import concern. ai
phantom-deps phantom-dep:@yiitap/extension-model-viewer AI (phantom-deps): Same-org sibling package, config-referenced. ai
phantom-deps phantom-dep:@tiptap/starter-kit AI (phantom-deps): Config-referenced, not code-imported; normal for editor extension registration. ai
phantom-deps phantom-dep:@yiitap/extension-table-wrapper AI (phantom-deps): Same-org monorepo package, expected phantom pattern. ai
phantom-deps phantom-dep:@yiitap/extension-video AI (phantom-deps): Same-org monorepo package, expected phantom pattern. ai
phantom-deps phantom-dep:@yiitap/core AI (phantom-deps): Same-org monorepo package, expected phantom pattern. ai
typosquat typosquat.levenshtein:vite AI (typosquat): Scoped package @yiitap/vue is a legitimate editor; Levenshtein match to 'vite' is incidental. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): uuid is a declared runtime dependency; phantom-dep heuristic misfires here. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped package @yiitap/vue is a legitimate editor; Levenshtein match to 'yup' is incidental. ai

Versions (showing 21 of 21)

Version Deps Published
0.19.2 3 / 3
0.19.1 3 / 3
0.19.0 3 / 3
0.18.2 3 / 3
0.18.1 3 / 3
0.18.0 3 / 3
0.17.1 3 / 3
0.17.0 3 / 3
0.16.3 50 / 3
0.16.2 50 / 3
0.16.1 50 / 3
0.16.0 50 / 3
0.15.0 49 / 3
0.14.0 49 / 3
0.13.0 8 / 3
0.12.0 7 / 3
0.11.2 7 / 3
0.11.1 7 / 3
0.11.0 7 / 3
0.10.0 7 / 3
0.9.0 56 / 3

v0.16.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.