@tscircuit/runframe
[tscircuit](https://github.com/tscircuit/tscircuit) ⋅ [View Examples](https://runframe.vercel.app)
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@tscircuit/footprinter | AI (phantom-deps): Same-org dep referenced in config; stable pattern. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-progress | AI (phantom-deps): Config-referenced external; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:cssnano | AI (phantom-deps): CSS build tool referenced in config; not a runtime import. | ai | |
| phantom-deps | phantom-dep:jscad-fiber | AI (phantom-deps): Referenced in config/externals; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:circuit-to-svg | AI (phantom-deps): Config reference; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:comlink | AI (phantom-deps): Build/config reference, not a missing runtime import; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:schematic-symbols | AI (phantom-deps): Config reference; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:tailwindcss-animate | AI (phantom-deps): Tailwind plugin referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tscircuit/file-server | AI (phantom-deps): Same-org dep; config reference pattern, stable false positive. | ai | |
| source-diff | encoded-string-file:dist/standalone-preview.min.js | AI (source-diff): Long strings in this minified bundle are CSS animations and schematic rendering logic from the Vite build process — not obfuscated payloads. Stable false positive for this circuit visualization package. | ai | |
| source-diff | encoded-string-file:dist/standalone.min.js | AI (source-diff): Long strings in this minified bundle are CSS animations and schematic rendering logic from the Vite build process — not obfuscated payloads. Stable false positive for this circuit visualization package. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 1863 versions and 17k weekly downloads; lack of provenance is consistent across all prior versions and is not a security concern here. | ai |
Versions (showing 100 of 1605)
| Version | Deps | Published |
|---|---|---|
| 0.0.1871 | 2 / 80 | |
| 0.0.1870 | 2 / 80 | |
| 0.0.1869 | 2 / 80 | |
| 0.0.1868 | 2 / 80 | |
| 0.0.1867 | 2 / 80 | |
| 0.0.1866 | 2 / 80 | |
| 0.0.1865 | 2 / 80 | |
| 0.0.1864 | 2 / 80 | |
| 0.0.1863 | 2 / 80 | |
| 0.0.1862 | 2 / 80 | |
| 0.0.1861 | 2 / 80 | |
| 0.0.1860 | 2 / 80 | |
| 0.0.1859 | 2 / 80 | |
| 0.0.1858 | 2 / 80 | |
| 0.0.1857 | 2 / 80 | |
| 0.0.1856 | 2 / 80 | |
| 0.0.1855 | 2 / 80 | |
| 0.0.1854 | 2 / 80 | |
| 0.0.1853 | 2 / 80 | |
| 0.0.1852 | 2 / 80 | |
| 0.0.1851 | 2 / 80 | |
| 0.0.1850 | 2 / 80 | |
| 0.0.1849 | 2 / 80 | |
| 0.0.1848 | 2 / 80 | |
| 0.0.1847 | 2 / 80 | |
| 0.0.1846 | 2 / 80 | |
| 0.0.1845 | 2 / 80 | |
| 0.0.1844 | 2 / 80 | |
| 0.0.1843 | 2 / 80 | |
| 0.0.1842 | 2 / 80 | |
| 0.0.1841 | 2 / 80 | |
| 0.0.1840 | 2 / 80 | |
| 0.0.1839 | 2 / 80 | |
| 0.0.1838 | 2 / 80 | |
| 0.0.1837 | 2 / 80 | |
| 0.0.1836 | 2 / 80 | |
| 0.0.1835 | 2 / 80 | |
| 0.0.1834 | 2 / 80 | |
| 0.0.1833 | 2 / 80 | |
| 0.0.1832 | 2 / 80 | |
| 0.0.1831 | 2 / 80 | |
| 0.0.1830 | 2 / 80 | |
| 0.0.1829 | 2 / 80 | |
| 0.0.1828 | 2 / 80 | |
| 0.0.1827 | 2 / 80 | |
| 0.0.1826 | 2 / 80 | |
| 0.0.1825 | 2 / 80 | |
| 0.0.1824 | 2 / 80 | |
| 0.0.1823 | 2 / 80 | |
| 0.0.1822 | 2 / 80 | |
| 0.0.1821 | 2 / 80 | |
| 0.0.1820 | 2 / 80 | |
| 0.0.1819 | 2 / 80 | |
| 0.0.1818 | 2 / 80 | |
| 0.0.1817 | 2 / 80 | |
| 0.0.1816 | 2 / 80 | |
| 0.0.1815 | 2 / 80 | |
| 0.0.1814 | 2 / 80 | |
| 0.0.1813 | 2 / 80 | |
| 0.0.1812 | 2 / 80 | |
| 0.0.1811 | 2 / 80 | |
| 0.0.1810 | 2 / 80 | |
| 0.0.1809 | 2 / 80 | |
| 0.0.1808 | 2 / 80 | |
| 0.0.1807 | 2 / 80 | |
| 0.0.1806 | 2 / 80 | |
| 0.0.1805 | 2 / 80 | |
| 0.0.1804 | 2 / 80 | |
| 0.0.1803 | 2 / 80 | |
| 0.0.1802 | 2 / 80 | |
| 0.0.1801 | 2 / 80 | |
| 0.0.1800 | 2 / 80 | |
| 0.0.1799 | 2 / 80 | |
| 0.0.1798 | 2 / 80 | |
| 0.0.1797 | 2 / 80 | |
| 0.0.1796 | 2 / 80 | |
| 0.0.1795 | 2 / 80 | |
| 0.0.1794 | 2 / 80 | |
| 0.0.1793 | 2 / 80 | |
| 0.0.1792 | 2 / 80 | |
| 0.0.1791 | 2 / 80 | |
| 0.0.1790 | 2 / 80 | |
| 0.0.1789 | 2 / 80 | |
| 0.0.1788 | 2 / 80 | |
| 0.0.1787 | 2 / 80 | |
| 0.0.1786 | 2 / 80 | |
| 0.0.1785 | 2 / 80 | |
| 0.0.1784 | 2 / 80 | |
| 0.0.1783 | 2 / 80 | |
| 0.0.1782 | 2 / 80 | |
| 0.0.1781 | 2 / 80 | |
| 0.0.1780 | 2 / 80 | |
| 0.0.1779 | 2 / 80 | |
| 0.0.1778 | 2 / 79 | |
| 0.0.1777 | 2 / 79 | |
| 0.0.1776 | 2 / 79 | |
| 0.0.1775 | 2 / 79 | |
| 0.0.1774 | 2 / 79 | |
| 0.0.1773 | 2 / 79 | |
| 0.0.1772 | 2 / 79 |
v0.0.1871
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1870
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1869
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1868
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1867
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1866
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1865
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1864
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1863
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1862
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1861
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1860
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1859
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1858
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1857
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1856
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1855
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1854
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1853
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1852
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1851
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1850
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1849
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1848
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1847
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1846
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1845
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1844
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1843
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1842
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1841
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1840
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1839
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1838
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1837
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1836
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1835
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1834
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1833
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1832
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1831
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1830
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1829
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1828
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1827
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1826
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1825
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1824
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1823
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1822
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1821
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1820
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1819
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1818
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1817
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1816
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1815
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1814
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1813
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1812
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1811
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1810
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1809
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1808
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1807
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1806
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1805
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1804
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1803
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1802
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1801
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1800
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1799
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1798
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1797
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1796
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1795
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1794
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1793
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1792
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1791
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1790
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1789
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1788
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1787
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1786
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1785
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1784
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1783
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1782
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1781
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1780
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1779
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1778
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1777
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1776
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1775
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1774
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1773
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1772
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.