← Home

@live-change/image-frontend

34
Versions
BSD-3-Clause
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

m8

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:rollup-plugin-node-builtins AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:rollup-plugin-visualizer AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:@live-change/dao-websocket AI (phantom-deps): Same-org monorepo dep; stable FP. ai
phantom-deps phantom-dep:@live-change/image-service AI (phantom-deps): Same-org monorepo dep; stable FP. ai
phantom-deps phantom-dep:primevue AI (phantom-deps): Config-file-only reference in a frontend package; stable false positive for this package. ai
phantom-deps phantom-dep:cross-env AI (phantom-deps): Used in npm scripts only; not a runtime import. Stable FP. ai
phantom-deps phantom-dep:primeflex AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:primeicons AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:compression AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:pretty-bytes AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:serve-static AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:get-port-sync AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:@live-change/cli AI (phantom-deps): Same-org monorepo dep used in scripts; stable FP. ai
phantom-deps phantom-dep:@live-change/dao AI (phantom-deps): Same-org monorepo dep; stable FP. ai
phantom-deps phantom-dep:v-shared-element AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:codeceptjs-assert AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:vue3-scroll-border AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:serialize-javascript AI (phantom-deps): Config-file-only reference; stable FP for this frontend package. ai
phantom-deps phantom-dep:@live-change/dao-vue3 AI (phantom-deps): Same-org monorepo dep; stable FP. ai
npm-metadata no-description AI (npm-metadata): Consistent with @live-change internal package pattern; not a malware indicator here. ai
provenance no-provenance AI (provenance): No provenance across the entire @live-change ecosystem; stable false positive for this publisher. ai
bogus-package bogus-package AI (bogus-package): Internal monorepo package from established @live-change org; sparse metadata is a consistent pattern across their 440+ versions. ai

Versions (showing 34 of 134)

Version Deps Published
0.9.104 27 / 7
0.9.103 27 / 7
0.9.102 27 / 7
0.9.101 27 / 7
0.9.100 27 / 7
0.9.99 27 / 7
0.9.98 27 / 7
0.9.97 27 / 7
0.9.96 27 / 7
0.9.95 27 / 7
0.9.94 27 / 7
0.9.93 27 / 7
0.9.92 27 / 7
0.9.91 27 / 7
0.9.90 27 / 7
0.9.89 27 / 7
0.9.88 27 / 7
0.9.87 27 / 7
0.9.86 27 / 7
0.9.85 27 / 7
0.9.84 27 / 7
0.9.83 27 / 7
0.9.82 27 / 7
0.9.81 27 / 7
0.9.80 27 / 7
0.9.79 27 / 7
0.9.78 27 / 7
0.9.77 27 / 7
0.9.76 27 / 7
0.9.75 27 / 7
0.9.74 27 / 7
0.9.73 27 / 7
0.9.72 27 / 7
0.9.71 27 / 7

v0.9.104

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.103

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.102

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.101

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.100

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.99

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.98

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.97

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.96

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.95

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.94

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.93

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.92

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.91

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.90

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.89

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.88

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.87

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.86

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.85

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.84

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.83

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.82

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.81

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.80

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.79

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.78

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.77

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.76

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.75

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.74

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.73

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.72

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.71

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.