← Home

vue-signature-pad

1
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

neighborhood999

Keywords

vuesignaturecomponent

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:merge-images AI (dependencies): merge-images is a well-known, legitimate npm package for merging images — directly relevant to a signature pad component's functionality. ai
dependencies unvetted-dep:signature_pad AI (dependencies): signature_pad is the canonical JS signature drawing library; its use is expected and appropriate for this Vue signature pad wrapper component. ai

Versions (showing 1 of 1)

Version Deps Published
3.0.2 2 / 34