← Home

vue-grid-layout

3
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

gmsa

Keywords

gridvuejsdragdraggableresizeresizablefluidresponsive

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): No behavior change; likely publish tooling variance for a stable long-lived package. ai
publish-pattern dormant-publish AI (publish-pattern): Long-established package with sporadic release cadence, no other risk signal. ai
phantom-deps phantom-dep:@interactjs/dev-tools AI (phantom-deps): Website package.json artifact; config-only reference. ai
phantom-deps phantom-dep:@interactjs/modifiers AI (phantom-deps): Website package.json artifact; config-only reference. ai
phantom-deps phantom-dep:@interactjs/auto-start AI (phantom-deps): Website package.json artifact; config-only reference. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires inside bundled vue.js in website/docs public folder, not library source code. ai
phantom-deps phantom-dep:@interactjs/auto-scroll AI (phantom-deps): Website package.json artifact; config-only reference. ai
phantom-deps phantom-dep:element-resize-detector AI (phantom-deps): Website package.json artifact; config-only reference. ai
phantom-deps phantom-dep:@interactjs/interactjs AI (phantom-deps): Website package.json artifact; config-only reference. ai
phantom-deps phantom-dep:@interactjs/actions AI (phantom-deps): Website package.json artifact; interactjs deps are referenced in config only, not imported. ai

Versions (showing 3 of 3)

Version Deps Published
2.3.12 6 / 11
2.3.11 6 / 11
2.3.10 6 / 11

v2.3.12

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: gmsa.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.