@tscircuit/runframe
[tscircuit](https://github.com/tscircuit/tscircuit) ⋅ [View Examples](https://runframe.vercel.app)
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@tscircuit/footprinter | AI (phantom-deps): Same-org dep referenced in config; stable pattern. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-progress | AI (phantom-deps): Config-referenced external; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:cssnano | AI (phantom-deps): CSS build tool referenced in config; not a runtime import. | ai | |
| phantom-deps | phantom-dep:jscad-fiber | AI (phantom-deps): Referenced in config/externals; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:circuit-to-svg | AI (phantom-deps): Config reference; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:comlink | AI (phantom-deps): Build/config reference, not a missing runtime import; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:schematic-symbols | AI (phantom-deps): Config reference; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:tailwindcss-animate | AI (phantom-deps): Tailwind plugin referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tscircuit/file-server | AI (phantom-deps): Same-org dep; config reference pattern, stable false positive. | ai | |
| source-diff | encoded-string-file:dist/standalone-preview.min.js | AI (source-diff): Long strings in this minified bundle are CSS animations and schematic rendering logic from the Vite build process — not obfuscated payloads. Stable false positive for this circuit visualization package. | ai | |
| source-diff | encoded-string-file:dist/standalone.min.js | AI (source-diff): Long strings in this minified bundle are CSS animations and schematic rendering logic from the Vite build process — not obfuscated payloads. Stable false positive for this circuit visualization package. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 1863 versions and 17k weekly downloads; lack of provenance is consistent across all prior versions and is not a security concern here. | ai |
Versions (showing 100 of 1605)
| Version | Deps | Published |
|---|---|---|
| 0.0.1771 | 2 / 79 | |
| 0.0.1770 | 2 / 79 | |
| 0.0.1769 | 2 / 79 | |
| 0.0.1768 | 2 / 79 | |
| 0.0.1767 | 2 / 79 | |
| 0.0.1766 | 2 / 79 | |
| 0.0.1765 | 2 / 79 | |
| 0.0.1764 | 2 / 79 | |
| 0.0.1763 | 2 / 79 | |
| 0.0.1762 | 2 / 79 | |
| 0.0.1761 | 2 / 79 | |
| 0.0.1760 | 2 / 79 | |
| 0.0.1759 | 2 / 79 | |
| 0.0.1758 | 2 / 79 | |
| 0.0.1757 | 2 / 79 | |
| 0.0.1756 | 2 / 79 | |
| 0.0.1755 | 2 / 79 | |
| 0.0.1754 | 2 / 79 | |
| 0.0.1753 | 2 / 79 | |
| 0.0.1752 | 2 / 79 | |
| 0.0.1751 | 2 / 79 | |
| 0.0.1750 | 2 / 79 | |
| 0.0.1749 | 2 / 79 | |
| 0.0.1748 | 2 / 79 | |
| 0.0.1747 | 2 / 79 | |
| 0.0.1746 | 2 / 79 | |
| 0.0.1745 | 2 / 79 | |
| 0.0.1744 | 2 / 79 | |
| 0.0.1743 | 2 / 79 | |
| 0.0.1742 | 2 / 79 | |
| 0.0.1741 | 2 / 79 | |
| 0.0.1740 | 2 / 79 | |
| 0.0.1739 | 2 / 79 | |
| 0.0.1738 | 2 / 79 | |
| 0.0.1737 | 2 / 79 | |
| 0.0.1736 | 2 / 79 | |
| 0.0.1735 | 2 / 79 | |
| 0.0.1734 | 2 / 79 | |
| 0.0.1733 | 2 / 79 | |
| 0.0.1732 | 2 / 79 | |
| 0.0.1731 | 2 / 79 | |
| 0.0.1730 | 2 / 79 | |
| 0.0.1729 | 2 / 79 | |
| 0.0.1728 | 2 / 79 | |
| 0.0.1727 | 2 / 79 | |
| 0.0.1726 | 2 / 79 | |
| 0.0.1725 | 2 / 79 | |
| 0.0.1724 | 2 / 79 | |
| 0.0.1723 | 2 / 79 | |
| 0.0.1722 | 2 / 79 | |
| 0.0.1721 | 2 / 79 | |
| 0.0.1720 | 2 / 79 | |
| 0.0.1719 | 2 / 79 | |
| 0.0.1718 | 2 / 79 | |
| 0.0.1717 | 2 / 79 | |
| 0.0.1716 | 2 / 79 | |
| 0.0.1715 | 2 / 79 | |
| 0.0.1714 | 2 / 79 | |
| 0.0.1713 | 2 / 79 | |
| 0.0.1712 | 2 / 79 | |
| 0.0.1711 | 2 / 79 | |
| 0.0.1710 | 2 / 79 | |
| 0.0.1709 | 2 / 79 | |
| 0.0.1708 | 2 / 79 | |
| 0.0.1707 | 2 / 79 | |
| 0.0.1706 | 2 / 79 | |
| 0.0.1705 | 1 / 79 | |
| 0.0.1704 | 1 / 79 | |
| 0.0.1703 | 1 / 79 | |
| 0.0.1702 | 1 / 79 | |
| 0.0.1701 | 1 / 85 | |
| 0.0.1700 | 1 / 85 | |
| 0.0.1699 | 1 / 85 | |
| 0.0.1698 | 1 / 85 | |
| 0.0.1697 | 1 / 85 | |
| 0.0.1696 | 1 / 85 | |
| 0.0.1695 | 1 / 85 | |
| 0.0.1694 | 1 / 85 | |
| 0.0.1693 | 1 / 85 | |
| 0.0.1692 | 1 / 85 | |
| 0.0.1691 | 1 / 85 | |
| 0.0.1690 | 1 / 85 | |
| 0.0.1689 | 1 / 85 | |
| 0.0.1688 | 1 / 85 | |
| 0.0.1687 | 1 / 85 | |
| 0.0.1686 | 1 / 85 | |
| 0.0.1685 | 1 / 85 | |
| 0.0.1684 | 1 / 85 | |
| 0.0.1683 | 1 / 85 | |
| 0.0.1682 | 1 / 85 | |
| 0.0.1681 | 1 / 85 | |
| 0.0.1680 | 1 / 85 | |
| 0.0.1679 | 1 / 85 | |
| 0.0.1678 | 1 / 85 | |
| 0.0.1677 | 1 / 85 | |
| 0.0.1676 | 1 / 85 | |
| 0.0.1675 | 1 / 85 | |
| 0.0.1674 | 1 / 85 | |
| 0.0.1673 | 1 / 85 | |
| 0.0.1672 | 1 / 85 |
v0.0.1771
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1770
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1769
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1768
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1767
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1766
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1765
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1764
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1763
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1762
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1761
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1760
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1759
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1758
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1757
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1756
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1755
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1754
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1753
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1752
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1751
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1750
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1749
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1748
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1747
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1746
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1745
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1744
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1743
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1742
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1741
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1740
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1739
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1738
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1737
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1736
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1735
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1734
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1733
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1732
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1731
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1730
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1729
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1728
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1727
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1726
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1725
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1724
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1723
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1722
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1721
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1720
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1719
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1718
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1717
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1716
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1715
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1714
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1713
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1712
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1711
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1710
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1709
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1708
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1707
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1706
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1705
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1704
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1703
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1702
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1701
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1700
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1699
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1698
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1697
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1696
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1695
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1694
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1693
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1692
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1691
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1690
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1689
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1688
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1687
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1686
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1685
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1684
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1683
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1682
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1681
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1680
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1679
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1678
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1677
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1676
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1675
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1674
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1673
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1672
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.