@yummacss/nitro
Fast CSS generation for Yumma CSS
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@yummacss/api | AI (phantom-deps): Same-org dependency; phantom-dep heuristic fires due to indirect/config usage, not a real concern. | ai | |
| phantom-deps | phantom-dep:globby | AI (phantom-deps): globby is a declared runtime dep used in config/build context; phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:tinyglobby | AI (phantom-deps): Bundled package; tinyglobby likely consumed transitively or at build time, not directly imported. | ai | |
| phantom-deps | phantom-dep:@yummacss/core | AI (phantom-deps): Same-org runtime dependency declared in package.json; heuristic false positive for this package. | ai |
Versions (showing 51 of 60)
| Version | Deps | Published |
|---|---|---|
| 3.29.0 | 3 / 0 | |
| 3.28.3 | 3 / 0 | |
| 3.28.2 | 3 / 0 | |
| 3.28.1 | 3 / 0 | |
| 3.27.0 | 3 / 0 | |
| 3.26.0 | 3 / 0 | |
| 3.25.0 | 1 / 2 | |
| 3.24.16 | 1 / 2 | |
| 3.24.15 | 1 / 2 | |
| 3.24.14 | 1 / 2 | |
| 3.24.13 | 1 / 2 | |
| 3.24.12 | 1 / 2 | |
| 3.24.11 | 1 / 2 | |
| 3.24.10 | 1 / 2 | |
| 3.24.9 | 1 / 2 | |
| 3.24.8 | 1 / 2 | |
| 3.24.7 | 1 / 2 | |
| 3.24.6 | 1 / 2 | |
| 3.24.5 | 1 / 2 | |
| 3.24.4 | 1 / 2 | |
| 3.24.3 | 1 / 2 | |
| 3.24.2 | 1 / 2 | |
| 3.24.1 | 1 / 2 | |
| 3.24.0 | 1 / 2 | |
| 3.23.0 | 1 / 2 | |
| 3.22.4 | 1 / 2 | |
| 3.22.3 | 1 / 2 | |
| 3.22.2 | 1 / 2 | |
| 3.22.1 | 1 / 2 | |
| 3.22.0 | 1 / 2 | |
| 3.21.2 | 1 / 2 | |
| 3.21.1 | 1 / 2 | |
| 3.21.0 | 1 / 2 | |
| 3.20.8 | 1 / 2 | |
| 3.20.7 | 1 / 2 | |
| 3.20.6 | 1 / 2 | |
| 3.20.5 | 1 / 2 | |
| 3.20.4 | 1 / 2 | |
| 3.20.3 | 1 / 2 | |
| 3.20.2 | 1 / 2 | |
| 3.20.1 | 1 / 2 | |
| 3.20.0 | 1 / 2 | |
| 3.19.0 | 3 / 0 | |
| 3.18.0 | 3 / 0 | |
| 3.17.0 | 3 / 0 | |
| 3.16.0 | 3 / 0 | |
| 3.15.0 | 3 / 0 | |
| 3.14.0 | 3 / 0 | |
| 3.13.0 | 3 / 0 | |
| 3.12.0 | 3 / 0 | |
| 3.11.0 | 3 / 0 |
v3.29.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.28.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.28.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.28.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.27.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.26.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.25.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.