json-joy
Collection of libraries for building collaborative editing apps.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:editing-traces | AI (npm-metadata): devDependency pointing to author's own repo for test traces; SHA-pinned, not shipped to consumers. | ai | |
| npm-metadata | url-dep:json-crdt-traces | AI (npm-metadata): devDependency pointing to author's own repo for test traces; SHA-pinned, not shipped to consumers. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process usage is in CLI test harness files (json-pack-test.js, etc.) that spawn the CLI binary for integration testing. Legitimate and expected for a CLI tool package. | ai | |
| phantom-deps | phantom-dep:nano-css | AI (phantom-deps): nano-css is a declared runtime dependency used in specific sub-modules of this large library; phantom-dep false positive for monorepo-style packages. | ai | |
| phantom-deps | phantom-dep:hyperdyperid | AI (phantom-deps): hyperdyperid is a declared runtime dependency; phantom-dep false positive for this large multi-module package. | ai | |
| phantom-deps | phantom-dep:@jsonjoy.com/json-type | AI (phantom-deps): @jsonjoy.com/json-type is a declared runtime dependency from the same author's ecosystem; phantom-dep false positive. | ai |
Versions (showing 100 of 324)
| Version | Deps | Published |
|---|---|---|
| 16.25.0 | 5 / 21 | |
| 16.24.0 | 5 / 21 | |
| 16.23.2 | 5 / 21 | |
| 16.23.1 | 5 / 21 | |
| 16.23.0 | 5 / 21 | |
| 16.22.1 | 5 / 21 | |
| 16.22.0 | 5 / 21 | |
| 16.21.0 | 5 / 21 | |
| 16.20.0 | 8 / 18 | |
| 16.19.0 | 8 / 18 | |
| 16.18.1 | 8 / 18 | |
| 16.18.0 | 8 / 18 | |
| 16.17.1 | 8 / 18 | |
| 16.17.0 | 8 / 18 | |
| 16.16.0 | 8 / 18 | |
| 16.15.0 | 8 / 18 | |
| 16.14.0 | 8 / 18 | |
| 16.13.2 | 8 / 17 | |
| 16.13.1 | 8 / 17 | |
| 16.13.0 | 8 / 17 | |
| 16.12.0 | 8 / 16 | |
| 16.11.0 | 8 / 16 | |
| 16.10.0 | 8 / 16 | |
| 16.9.0 | 8 / 16 | |
| 16.8.0 | 8 / 16 | |
| 16.7.0 | 8 / 15 | |
| 16.6.0 | 8 / 15 | |
| 16.5.0 | 8 / 15 | |
| 16.4.0 | 8 / 15 | |
| 16.3.0 | 8 / 15 | |
| 16.2.0 | 8 / 15 | |
| 16.1.0 | 8 / 15 | |
| 16.0.0 | 8 / 15 | |
| 15.11.0 | 8 / 15 | |
| 15.10.0 | 8 / 15 | |
| 15.9.0 | 7 / 15 | |
| 15.8.0 | 7 / 15 | |
| 15.7.0 | 7 / 15 | |
| 15.6.0 | 7 / 15 | |
| 15.5.0 | 7 / 15 | |
| 15.4.1 | 7 / 46 | |
| 15.4.0 | 7 / 46 | |
| 15.3.0 | 7 / 46 | |
| 15.2.0 | 7 / 46 | |
| 15.1.0 | 7 / 46 | |
| 15.0.0 | 7 / 48 | |
| 14.4.0 | 7 / 48 | |
| 14.3.0 | 7 / 60 | |
| 14.2.0 | 7 / 60 | |
| 14.1.1 | 7 / 60 | |
| 14.1.0 | 6 / 89 | |
| 14.0.0 | 4 / 89 | |
| 13.0.0 | 4 / 89 | |
| 12.6.0 | 4 / 89 | |
| 12.5.0 | 4 / 89 | |
| 12.4.0 | 4 / 89 | |
| 12.3.0 | 4 / 89 | |
| 12.2.0 | 4 / 89 | |
| 12.1.0 | 4 / 89 | |
| 12.0.0 | 4 / 89 | |
| 11.43.0 | 4 / 89 | |
| 11.42.0 | 4 / 88 | |
| 11.41.0 | 4 / 88 | |
| 11.40.0 | 4 / 88 | |
| 11.39.1 | 4 / 88 | |
| 11.39.0 | 4 / 88 | |
| 11.38.1 | 4 / 88 | |
| 11.38.0 | 4 / 88 | |
| 11.37.0 | 4 / 87 | |
| 11.36.0 | 4 / 87 | |
| 11.35.0 | 3 / 87 | |
| 11.34.0 | 3 / 87 | |
| 11.33.0 | 3 / 87 | |
| 11.32.1 | 3 / 87 | |
| 11.32.0 | 3 / 87 | |
| 11.31.0 | 3 / 87 | |
| 11.30.0 | 3 / 87 | |
| 11.29.0 | 3 / 87 | |
| 11.28.2 | 3 / 87 | |
| 11.28.1 | 3 / 87 | |
| 11.28.0 | 3 / 87 | |
| 11.27.0 | 3 / 87 | |
| 11.26.0 | 3 / 86 | |
| 11.25.0 | 3 / 86 | |
| 11.24.0 | 3 / 86 | |
| 11.23.0 | 3 / 86 | |
| 11.22.0 | 3 / 86 | |
| 11.21.1 | 3 / 86 | |
| 11.21.0 | 3 / 86 | |
| 11.20.0 | 3 / 86 | |
| 11.19.0 | 3 / 85 | |
| 11.18.0 | 3 / 85 | |
| 11.17.0 | 3 / 85 | |
| 11.16.0 | 3 / 84 | |
| 11.15.0 | 3 / 84 | |
| 11.14.0 | 3 / 84 | |
| 11.13.0 | 3 / 84 | |
| 11.12.0 | 3 / 84 | |
| 11.11.0 | 3 / 84 | |
| 11.10.0 | 3 / 84 |
v16.25.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.24.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.23.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.23.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.23.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.22.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.22.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.21.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.20.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.19.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.18.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.18.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.17.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.17.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.16.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.15.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.13.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.13.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.13.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.9.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v16.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.9.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.