npmreport

npm gives maintainers mechanisms to verifiably establish how a package was published.

Staged publishing
Published through npm's staged flow, prepared and reviewed before it goes live. npm docs ↗
Trusted publisher
Published from CI over OIDC, with no long-lived npm token to leak or steal. npm docs ↗
Provenance
A signed link from the published package back to the exact source commit and build. npm docs ↗
None
No verifiable signal. The release rests on the maintainer's account and token alone, so a compromise there can ship malware unnoticed.

In the summary, staged publishing and trusted publisher both count as strong trust; provenance is a weaker positive; none is the one to check.

Audit of Vue, generated . This is a read-only snapshot.
Run your own audit →

Audit of Vue

Re-run this audit
Tracking daily next

Progress over time

Strong trust
28.7% (33) staged or trusted
Any trust
29.6% (34) incl. provenance
No trust signal
70.4% (81) no trust metadata detected
Strong trust Any trust No trust signal
0%50%100%8/98/279/7
  1. ...
    34/115 any trust
  2. [viewing]
    0/0 any trust
  3. 34/115 any trust
  4. 34/115 any trust
  5. 34/115 any trust
  6. 34/115 any trust
  7. 0/0 any trust
  8. ...
    34/115 any trust
  9. 34/115 any trust
  10. ...
    34/115 any trust
  11. 0/0 any trust
  12. 34/115 any trust
  13. 34/115 any trust
  14. 34/115 any trust
  15. 34/115 any trust
  16. 34/115 any trust
  17. 34/115 any trust
  18. 34/115 any trust
  19. ...
    34/115 any trust
  20. 34/115 any trust
In scope
0
Staged publish
0
Trusted publisher
0
Provenance only
0
No trust signal
0
Deprecated latest
0
0 packages · click a column to sort
Package trust level report