{"_id":"transpareo-time-machine","_rev":"31-9caffe6d8e464c3d81663827ab34a552","name":"transpareo-time-machine","dist-tags":{"latest":"2.18.1"},"versions":{"0.0.0":{"name":"transpareo-time-machine","version":"0.0.0","license":"GPL-3.0-or-later","_id":"transpareo-time-machine@0.0.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"b7a2ff9a18c49eb5467ab9db20facdfde2f85a77","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-0.0.0.tgz","fileCount":2,"integrity":"sha512-4I1SA6/U+7SKYGnfmnYLsYDzmnCKMccTtmzKgYz6rF1pVKEXKGmvNEr/9cJTvkP26qrBh9vZsINV+qzCD2HbaA==","signatures":[{"sig":"MEUCIQCtd/MwYfAwI2Y6hLIasifmEytoeQawnhd5mXqizd6VvQIgPUPfZqQgqmtZvGF5uPtyvb3XwU741syo79erE49+mhs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":561},"private":false,"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"11.13.0","description":"Name reserved; first public release coming soon.","directories":{},"_nodeVersion":"25.9.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_0.0.0_1780495456746_0.30182445521913115","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"transpareo-time-machine","version":"1.0.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@1.0.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"8ebe111e221731b928581c2fdffb41ed249d8e0d","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-1.0.0.tgz","fileCount":95,"integrity":"sha512-Wf2EYelcAPp+54U4k+jk/4x1Vc8yvGl28lCS5+NXg7Ae0gCmFA6B+Na0GyIKsRDdr+U+Z1XLzJXi/piqsk2E0g==","signatures":[{"sig":"MEQCIAg3Ie4yk9MSKn6ZUXQqfubIbL9iW1DDynsX0uWJR7yRAiA/0ft6K41La20hcucmHeDv/O8h77J9fDkyK5PMnqUawg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1157912},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"0cb7cf2e1b6d9b6a8eafe4c3436e6fb9707ea1de","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.22.3","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_1.0.0_1781708612216_0.13118103888789245","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"transpareo-time-machine","version":"2.0.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.0.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"94a1ae652e948d96f5338952eb7354dd3947d9fd","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.0.0.tgz","fileCount":95,"integrity":"sha512-rdZLOFaxQ73sHQd5ndtQtdtFyhN1LvgIf2n5yXSBFtpOHarN7dkMgS6QzWWx+xEFeIiJjQ4KTOjGO/UKL50JSw==","signatures":[{"sig":"MEQCIHA2ky/OD0ahoVJCF+687M6GWUQScG0XtaVHx1enKygiAiBIjccjF6+6R4J/lU+4FE97ZaocP+bvK+JDLUVLMt2i5w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1160781},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"478eb07236e11e9a58842c20f66932f9a606251f","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.22.3","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.0.0_1781971921334_0.6975959726606227","host":"s3://npm-registry-packages-npm-production"}},"2.0.1":{"name":"transpareo-time-machine","version":"2.0.1","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.0.1","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"fc03c99503781872b77b2e6c0d5ee7e0b43928ca","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.0.1.tgz","fileCount":95,"integrity":"sha512-VS5EOOER7O1RClGryaEMLQGLrrom2PWRA9j+ChET1kXCH3RnCk/+F0DinQtYWCm/9+eYdqFb17AZFHLS0jfWtQ==","signatures":[{"sig":"MEUCIQD+gzsFtR9AJCz07NA7N9nU7T8Qyxs5YE7Wv05AdswDNwIgHrhHY71k3qEnoNzx+ZRFmeaxS0nPsT2J2hLNKWnLvVs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1169400},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"a94590365599000d855e9293d0ba6c9bdb4ac20e","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.22.3","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.0.1_1782191407261_0.16690683711134202","host":"s3://npm-registry-packages-npm-production"}},"2.1.0":{"name":"transpareo-time-machine","version":"2.1.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.1.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"de850243ccfe18f383ca3f704c1d87a5dbbfa71d","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.1.0.tgz","fileCount":95,"integrity":"sha512-GkaYDRXrCjvTRd/lgSxw/F7lWy6gy7m6NDsXx8mPuZNxJRhTf+K3lmfbDIGDq3zKPgHKJYD3UOKrPiM2hRfskw==","signatures":[{"sig":"MEQCIEM43gjtygKMBYrH7tIdaCcLHliN0SL3rp524Sd7Wj/sAiBNy3wPTMi7PXOtY8RGb+1vNmXDZrDLxIKs7faqYRnfkw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1171524},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"60025ce0836d039309168753d50c9b5c5ce3b549","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.0","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.1.0_1782389843937_0.4419569456891139","host":"s3://npm-registry-packages-npm-production"}},"2.2.0":{"name":"transpareo-time-machine","version":"2.2.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.2.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"d76a0c061ab7a66530e8e36d8f6715ebad151f37","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.2.0.tgz","fileCount":97,"integrity":"sha512-QZYAb+NNfceUY9d6YtBNCHokl35UXOnrnDzFmBFZIjN1tP1EkpZAvkhNluxSeOCOVZBHqHRXuUXD9Bypl7qVhQ==","signatures":[{"sig":"MEQCICCUqKUyRiaCKR/kUC029gTCPE2Nm6zJbyBJhYZt3sbaAiBsFuHZxeC+bCDCmu3VkrAaSzspVgtPV7BFX2pxhUS/yQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1188862},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"31615d93c9b0d5f4fadb74c0fc1abae6bf77a871","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.0","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.2.0_1782644246467_0.32443826169242307","host":"s3://npm-registry-packages-npm-production"}},"2.3.0":{"name":"transpareo-time-machine","version":"2.3.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.3.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"8886d77efd7bb59b22bdc7f73114cccd28dea401","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.3.0.tgz","fileCount":97,"integrity":"sha512-/ESylF7ahPAyI/UxPeWr6z0QduQNGFZF75UARzNQD5YLOh1aBjx0tPY1vkiAnPD7KaOmwbS7I2rkIOGtBNm5Bw==","signatures":[{"sig":"MEQCIHgwCPTEEdCaXv6xIR5jRL/VJOB7Bbh8vrpLvOTJ10byAiABF9nWPQ8WVayVXwHB9Tio5hfWL7PLOPLzCFhOX+vMaQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1188916},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"51cb0222b962eeca9f46b99b47ffcdfd1195adb1","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.3.0_1783005955058_0.12866190883816175","host":"s3://npm-registry-packages-npm-production"}},"2.4.0":{"name":"transpareo-time-machine","version":"2.4.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.4.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"9fa54207a941ca6a00c7a672323ef947897dc0a6","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.4.0.tgz","fileCount":97,"integrity":"sha512-XAWC95WvZ15pyrsNzxclknbODiNA1VgKUIDie0ov0xbAk/alZHc+CL/FC2uZZeeXHvCWF8NOTF7iugu819tO5w==","signatures":[{"sig":"MEQCID0KuEG9ozPt0VnSXVEuAkFttSZTKzLw/6vJBcKoNv7XAiAmU0nai9bN/RLS2RDlgwcbmLxjAYNnf8oEvkHOEHqgZw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1190089},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"fcca87344e8bd6ad981df7713317892958bda34d","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.4.0_1783019278298_0.896464867234491","host":"s3://npm-registry-packages-npm-production"}},"2.5.0":{"name":"transpareo-time-machine","version":"2.5.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.5.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"98c53ef7736b95b634060a7b3547d150eaeda3d3","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.5.0.tgz","fileCount":97,"integrity":"sha512-oLIoIrrTq61D0O2jtl0RE6BL5xuirDWU9ztZfNgDisjen8rRJtmH5qXQJ9LGKhBIhgBFNZtk9oHevY1CUzc2dQ==","signatures":[{"sig":"MEQCIFxzIjnclPSu03EMVCZDLHo5UZDbI5ykbQ9n3cHPLJYCAiA26Wv4xAlIGCbcGfGrUWR2hAoM28HiQReLMorgLiivmQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1270760},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"3eef2531259797741130b093b4656e4fa5fd9b6e","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.5.0_1784877136026_0.4951980084100016","host":"s3://npm-registry-packages-npm-production"}},"2.5.1":{"name":"transpareo-time-machine","version":"2.5.1","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.5.1","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"0e6ed09312359c61a5113333a176e3ff90f99505","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.5.1.tgz","fileCount":97,"integrity":"sha512-XIbLeBnBX7ekXp1EryTD6FHVCRYPFoNzGmmZnUVcHy1GLXjEvYMiJUB+PVEwiT6XFh3hfzLycFQXAZOKwL5QLw==","signatures":[{"sig":"MEYCIQDnBQuok1hXuQIqMy2hsY8ZZ2b/cOOz89qMxd8y09UMNQIhANEjSFM9t/LvpWTqudreIZ/yuuMHZuN2w+4c/G53/xTJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.5.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1274148},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"3431e9ebad5ef735150843722aab518a83f80d2c","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.5.1_1784901516309_0.7002535364607998","host":"s3://npm-registry-packages-npm-production"}},"2.5.2":{"name":"transpareo-time-machine","version":"2.5.2","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.5.2","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"cd54440e2c194d8aeaaae0c70d2adcf121a1a061","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.5.2.tgz","fileCount":97,"integrity":"sha512-l4xfoBPRRBV1u9+3gjImkA1PGjgkksngQWJpLn/OYLFKyTt/Xa5AEOgk6ZuXBdIJrq6qG5aBNfb1FD8TY4hbzQ==","signatures":[{"sig":"MEQCIGbf/GC6OeMiS7dO7kLcE5Pu8Fz1q5b7zFZBO42aOiHmAiAc+IkX/7UQ+iibakzu/jNJG/8GeVlocWydmzFdkWQkdA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.5.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1274645},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"5f037dfde8d991939dc6376e54e57d203eee9f22","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.5.2_1784961393996_0.04767284766971991","host":"s3://npm-registry-packages-npm-production"}},"2.6.0":{"name":"transpareo-time-machine","version":"2.6.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.6.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"9af60a32d2ec9157c407ae74147fc45bf8edb276","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.6.0.tgz","fileCount":97,"integrity":"sha512-0ZUptxyRxqxOWzEqkITvLdvBnQc3ur0fGs2JCeT9464Zt4v1LV8x83bQU+GqzEJ2NI49lf/e+q+gaIaPidPNXA==","signatures":[{"sig":"MEQCIG5vcj/jl3zBf0NsvFGe9oHaCkMEM0pfUmmfYlJMm366AiAgMEGYj7aWuNoH15J6iDHzW+rxXUzP2u4jU9ZgO6U1cA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1280741},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"db4b90e6620e5a19b7760599e93f3791c93aaea0","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.6.0_1785506317883_0.10226090978781466","host":"s3://npm-registry-packages-npm-production"}},"2.7.0":{"name":"transpareo-time-machine","version":"2.7.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.7.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"c794a2de5a5bb7c54006025f6a5efa18cd94bda1","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.7.0.tgz","fileCount":97,"integrity":"sha512-VxtSw7OLMHYQVv6BT+4gSAhksDmHIY5btVoNG5mPvDTZLCAzigvQ7olCvrPboYdsi0YBndNtg3Wp+M4Vv+r6hA==","signatures":[{"sig":"MEUCIAZeCTbQnJXjUfFBQzNg/LgWFXXwIDemaFoJ91EHlpm6AiEAnq89EiSxxC6MB001hX/9nFY2ThTiCdUinFs9VaWG4ZI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1282921},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"e5dca73f69c76df70db317f9f1dae4248f725db2","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.7.0_1786206672621_0.4305019122863927","host":"s3://npm-registry-packages-npm-production"}},"2.8.0":{"name":"transpareo-time-machine","version":"2.8.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.8.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"0fefbb4a0ac7a6ed14f6e34d3426aa7b3371c041","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.8.0.tgz","fileCount":97,"integrity":"sha512-mf3DTrOkPYNbqGoLemfPViZQyz21/cyPViqWulFv+/DybY0NcAJaRJejxlkS3nYAvVW6OdwCZ+tuuGa3uTZreQ==","signatures":[{"sig":"MEQCIB3ZsDAkkN/O++Aqv2CBRyppVnoEO7lvAmi10h/BMjbQAiA4abgKiKwEfrSrQ3oO6Aphfx9C5HJVUOh6hgRk4INs4w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1289802},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"d3c29137a5759c626d655c59561279d54a029b4e","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.8.0_1786271688925_0.8786058014852771","host":"s3://npm-registry-packages-npm-production"}},"2.8.1":{"name":"transpareo-time-machine","version":"2.8.1","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.8.1","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"b09a863e0029d6c42389a9861990b9ed0c15ee46","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.8.1.tgz","fileCount":97,"integrity":"sha512-WIqb3z5s/OxfBWnt44QzbOLMFFIsqKsk+Eau2olrcuhgx6Lm+vwqSEczBZNgWSWvQa/WfXLuEF96xOpTDPD6+w==","signatures":[{"sig":"MEUCIQDBQ2VbBsRX05HK9ihKXwxx+7LnZSqouxvSV91sJ83nDQIgWWPj7/+ef15KUVL9A117sxhyhkMeRQuZjUANIT2YHPk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.8.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1300637},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"b21ae5c3c6d2d79bb9cb379974cb742ed5c98e70","scripts":{"dev":"vite","a11y":"playwright test","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.8.1_1786525145195_0.9390715805046654","host":"s3://npm-registry-packages-npm-production"}},"2.9.0":{"name":"transpareo-time-machine","version":"2.9.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.9.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"07341903729d74646ae620eeb240b3d9926f89a7","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.9.0.tgz","fileCount":97,"integrity":"sha512-fDh6mBJoSPQCnz79vWNYqBHSN/FpgEcEPn6c3Loiz0EvDyC9JnftZqa8fHwT+7oi9l+eV1u/lp92hay2FfTbng==","signatures":[{"sig":"MEUCIQCB8p28WFL6bl8xKw7+05NVpPCT06o/Hw5M1qBDTd67+QIgcV8KUAzN18X5cK896FuJQruVzR1UeX6c+GcqtSR+me8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1304654},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"129d34c110be0afd183f0f7f04d5f7312ad9ede1","scripts":{"dev":"vite","a11y":"npm run browser --","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.9.0_1786547252843_0.5953856117183709","host":"s3://npm-registry-packages-npm-production"}},"2.10.0":{"name":"transpareo-time-machine","version":"2.10.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.10.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"f9688cd80d7f92e51612862a3a7ec668e9281cac","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.10.0.tgz","fileCount":97,"integrity":"sha512-WaSZcihJhJiI/Ntl50K9xGivz0CwMFkSg50VrgEVufNNnHjfS3jCY37oFV/nQ2pwYI3hMa7QWP1kSzxLK+iqRg==","signatures":[{"sig":"MEUCIGDxqoLLTTK8R+UokFKxJ/l36ew1YWNl84ymEtyd+SZ7AiEAqXTHooxk/Fc8Ekgm+I2C0Mab6mKVJf335+SFL+fDN9k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1385183},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"d79f25e9d4a68c19717a80bf68c4325382f90f3a","scripts":{"dev":"vite","a11y":"npm run browser --","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.10.0_1787089957438_0.1510709521982565","host":"s3://npm-registry-packages-npm-production"}},"2.11.0":{"name":"transpareo-time-machine","version":"2.11.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.11.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"f21b6f4647bdd094441bfa8c75c6cae8a788d018","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.11.0.tgz","fileCount":97,"integrity":"sha512-B3V2pPuobtCPonS2UFCZv9d3OOIJ1aZc/Gp67SzD5+u8LzIU+KPoQD/X239UIjsGZOMk3Xq8ydSvNlOhPcNPkA==","signatures":[{"sig":"MEQCIHOcY3lMirr7b5O2R3lXKt9NGy/9pt5vkMtpxRI53nUsAiBKIWez98KgV/g1SkdWHqZA3apL35GYjfRm6Pz7F1OPrw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.11.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1387124},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"7600f96acec47ff400e848bbb30e7b4a13d07724","scripts":{"dev":"vite","a11y":"npm run browser --","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.11.0_1787115420084_0.1771461862093493","host":"s3://npm-registry-packages-npm-production"}},"2.12.0":{"name":"transpareo-time-machine","version":"2.12.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.12.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"d898c96353fad787c20c558dbd61cc2971abca7b","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.12.0.tgz","fileCount":97,"integrity":"sha512-zDVId20lpwO3/Mq057AjkaVhB2dlFO7NEhEaokgJ0mNnhaAgZ3uw8m3ZMaiZy6E5Nk9m7LYlCKDxVe8/lq5+CQ==","signatures":[{"sig":"MEUCIQD9ayYCXrrq9K/SAsUyfdrb9rezWXHqnjI2ElU7YvobVwIgIT7FJQJwiJr12lCsrmEWNL5bMji8ehjglk2jy9omKMs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.12.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1388220},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"cf8afd5f0d807c3c6813d9aea806dbb2e9cdb313","scripts":{"dev":"vite","a11y":"npm run browser --","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.12.0_1787174079563_0.41448790107595546","host":"s3://npm-registry-packages-npm-production"}},"2.12.1":{"name":"transpareo-time-machine","version":"2.12.1","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.12.1","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"622037f74fafbba8085637f99bb58b52f2e38b33","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.12.1.tgz","fileCount":97,"integrity":"sha512-GeJZOsQEtinbkS6mNacgpLLv2aMgl3/GrBuOv084mm0/JRUG1XY749gNhpJXfRm2cyicU72D5LUtWw9rrQdoTA==","signatures":[{"sig":"MEUCIQDWsO6O95pus6/vlmYd3/Y0uvNmCXnp+rPMQLJ9fpqufwIgQktixR0SE0lEWbWEzWM39S/xoplnM0GLEbo3Xl4W1cA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.12.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1391654},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"90e1eb60d11e5b7b7b98ebb105728b061c35d15b","scripts":{"dev":"vite","a11y":"npm run browser --","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.12.1_1787180432420_0.6861249034821544","host":"s3://npm-registry-packages-npm-production"}},"2.12.2":{"name":"transpareo-time-machine","version":"2.12.2","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.12.2","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"c77c16e949d7427b953a91b8484b837f991f14a1","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.12.2.tgz","fileCount":97,"integrity":"sha512-tYVXcqF87d/j4Y+nLqN/FIK6paT9Mm2gUBEOZbGWOJF6QUoZRuM5rqlVeYPuedJvI7m1fZnEaJQ1+pIQkMY4mg==","signatures":[{"sig":"MEUCIQDWF92xtwqmoC8Ql9e4CQ5Bxsit0otCk06W10GJ+yLbIQIgOESubDXr/3aUu6CA4RVQ4JT9Fx53DEQURS8kRk4EpLE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.12.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1395064},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"6a3ed45b6eca07e3ec9676e0cc8260c6f2ba79ac","scripts":{"dev":"vite","a11y":"npm run browser --","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.12.2_1787182742601_0.7938784529107328","host":"s3://npm-registry-packages-npm-production"}},"2.13.0":{"name":"transpareo-time-machine","version":"2.13.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.13.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"a5b22197c54287847ed9771fdde4fc384e05b265","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.13.0.tgz","fileCount":97,"integrity":"sha512-ifRMImVzJAq6E/dvbSr86g4WtCaYKSt1FmqkzlyoJl40H3ldnzMk+Fj3a1LtBfW3HaKzIMzkvqVWCBFuHuOBEw==","signatures":[{"sig":"MEQCIF54h4z+CoODxDYy3YI6M1rb7dWBmhpgEC991zIBxbfUAiB6qCRkp0KjUpYk2kjXGA/J5Nyu30+Q1sjDfwu51xnT9g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.13.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1400345},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"e51edb8d72aff319dbb52884dbafcf3faf110b71","scripts":{"dev":"vite","a11y":"npm run browser --","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.13.0_1787206797167_0.34081074677084255","host":"s3://npm-registry-packages-npm-production"}},"2.14.0":{"name":"transpareo-time-machine","version":"2.14.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.14.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"202c3807f96b0df61d7acd1787a4ddc456794dad","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.14.0.tgz","fileCount":97,"integrity":"sha512-pD9X2AEVbBDeyYWNNo+ZDWLUd6qvYunCL4oRLHmEvf3akdRT2957OKsh45N4acP/IsAo18Dr7nI/XbvL0L7Kow==","signatures":[{"sig":"MEUCIQCSVIivqQ3hgBDJfpjrgWfVu9uisQs62m4HTGl6jHN1HwIgWNWRaORe0nv3r+7RRanr0J2WIFY/uFmfO2SW/2ph6xY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.14.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1411106},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"b840be592000b012eb0744dc291397261cd1e06c","scripts":{"dev":"vite","a11y":"npm run browser --","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.14.0_1787280698545_0.717220195920026","host":"s3://npm-registry-packages-npm-production"}},"2.14.1":{"name":"transpareo-time-machine","version":"2.14.1","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.14.1","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"37509b8c0799bb340943ce72cef517add526c0ef","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.14.1.tgz","fileCount":97,"integrity":"sha512-WxBJFiOLe3W2go0LDQAgL9q1V9iZzjVeP9MXYhbfyPRkCsOKeoXmBZAgrB5s9Npo8ZqXXKONwZqKSf2kUaCj2Q==","signatures":[{"sig":"MEUCIQDFIddKVl0Gh1zDGxKwWucl415fHvLoh2lvUmYrMf14wAIgU7qbVtmCkobwpOO/JQgKQP+c0TAambC3V5BCAFKNbII=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.14.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1412214},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"44d664bb5f18bc34b6936bf157162d8c96657b10","scripts":{"dev":"vite","a11y":"npm run browser --","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.14.1_1787284008871_0.1636858710548712","host":"s3://npm-registry-packages-npm-production"}},"2.14.2":{"name":"transpareo-time-machine","version":"2.14.2","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.14.2","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"664bef7dc3146619035f84a15c9a8f28e9816464","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.14.2.tgz","fileCount":94,"integrity":"sha512-bixPyLUZ6IFhf/5yGrEOGQXbL53t79QPy7YpAkQ4P8HqYp+omFUD6G+WxnWHvQo498nSkUD6NkzVTnxh+WZp8g==","signatures":[{"sig":"MEQCIF/XLMtYOZwzk94/AGNJIQzS30QXQQMNWu9+yOUtzWNVAiBmgpslbe9YmLRn+zg/B/XhSvSgqmcL0kynSybxY9HLzA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDB1NunVRfMTYQhaA3LKVoCMpW/oRH2ivZGMgknhV6yzgIgcdKJA4t/KcN5scde9YTN83ySf7rbXz9GtyJ1c54d6JA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.14.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1436948},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"973fb7ed12bf3b1b16f9f85df4794e58e9de8be4","scripts":{"dev":"vite","a11y":"npm run browser --","demo":"tsx scripts/demo.ts","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts --mode embed && vite build --config vite.embed.config.ts --mode dpp-verifier","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","terser":"^5.51.2","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.14.2_1789122171754_0.8604994009105178","host":"s3://npm-registry-packages-npm-production"}},"2.15.0":{"name":"transpareo-time-machine","version":"2.15.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.15.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"7ffca6ac0f6685961f6e725cef8ecd472edf8e33","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.15.0.tgz","fileCount":94,"integrity":"sha512-Xnp47a+91b8pCF0GBg41uAO2xKbM3SZ8Ld+gNCIcb3jQDfva30FVknZih/spcpaEU9wUDhOgg1chIaqZh+qorw==","signatures":[{"sig":"MEUCIQCICizZqgxTSa23ZLS9INu+xXmd6bt50seh0xY9HbL0RgIgISQ+ioR5RhWo/NX+3xgmFagH36XG1uCuRMl/dzs9piU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCpr6Qbb3/ZhAHvruMeaRHkq96jPDX/QmlD2Wgc80TH7gIhAM3FF319B3Qk0vCz4utpCR6DJV4y491xZ/dhzJZfOkVi","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.15.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1446296},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"6cbbd2997a05655b0b77fa208f17919a1872eadb","scripts":{"dev":"vite","a11y":"npm run browser --","demo":"tsx scripts/demo.ts","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts --mode embed && vite build --config vite.embed.config.ts --mode dpp-verifier","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","terser":"^5.51.2","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.15.0_1789172593325_0.8706414430796883","host":"s3://npm-registry-packages-npm-production"}},"2.16.0":{"name":"transpareo-time-machine","version":"2.16.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.16.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"3798cd24f67b733a49b4bf100392e939f6d77fbd","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.16.0.tgz","fileCount":94,"integrity":"sha512-eT8mdj5gDbLmkpJX/grgtzp3OqtM/KTn47qrRdu1+/lpSxb2pVYlU1PEjoaaAeB0T0lf/wiJcbTOCbxadWHmig==","signatures":[{"sig":"MEUCIQC9f4KaVnR4/4yeJMN7IBUdMEosN2gr1lnHayMVDgvJ9wIgUT4w3fLg28M9PDDQS4P7kDVofq0H1gIdbgEi1ZJBnUU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDmiGk2iuBTAX2kudl1AjC9vWo9HKCeGqfY3yz0XjJVQgIgMR2HT/DUWy3rnY6ERXYjguJy09xnqQE2SXW4aWqOkrU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.16.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1580480},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"05bf606be8f49fec44169da822099b6b0d6ad245","scripts":{"dev":"vite","a11y":"npm run browser --","demo":"tsx scripts/demo.ts","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts --mode embed && vite build --config vite.embed.config.ts --mode dpp-verifier","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","terser":"^5.51.2","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.16.0_1789347836554_0.19617427263669396","host":"s3://npm-registry-packages-npm-production"}},"2.16.1":{"name":"transpareo-time-machine","version":"2.16.1","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.16.1","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"cb26eec51b5d9273a89adf19aa67604e9c58856a","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.16.1.tgz","fileCount":94,"integrity":"sha512-ImNZgdSpYJb/pZ17uPDjKGwRkXhlyyLzx+GiQtrDTUPxGxIa3SYWSACoswbj73/mK//2G27FPYzQqpr640GnTw==","signatures":[{"sig":"MEUCIQChp1kveS4HKO0rXA3DODswqrwTHjwY22neUhWmRlANgQIgSQDDOCfa4V79N3Ww70lOuOy0aUXgGPITRxEgZyvn4kg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIC/XoJQVBjbrLMV7FFxtcFHEmGTCw79j8uNRJLYV3/9FAiAIwi85nzxJl5/Kl9XY+OabGCP/3Aa9uxu6c0mAtrqrFw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.16.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1593228},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"e5fdef76147d8237170eecdf471d81510dcee7bf","scripts":{"dev":"vite","a11y":"npm run browser --","demo":"tsx scripts/demo.ts","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts --mode embed && vite build --config vite.embed.config.ts --mode dpp-verifier","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","terser":"^5.51.2","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.16.1_1789356987370_0.11542796727475113","host":"s3://npm-registry-packages-npm-production"}},"2.17.1":{"name":"transpareo-time-machine","version":"2.17.1","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.17.1","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"83684b82c07786880742e51ddc7acf5add09d4ab","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.17.1.tgz","fileCount":94,"integrity":"sha512-TwpyIq8wE2wsBR/rgWyqYMff/vA3ZCo5CbHNRo9rneZ2g7t0INlftZgB+tNtqMHfb0Hq6nqwg97fnouVDDlUFQ==","signatures":[{"sig":"MEQCIEY9MQpYrOk/IpCvAIxq0LYXzmvauRTr1MXir+pQMdKOAiBo9A+K0YjiL+S8ZPnS2v6jp8SiEZFd4US0OuC7mQ/0+A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQC5OoZr0O6jLbX7ZoypUbQE4o2iVMJ+J+3iKKWiiBTYmQIhAOnES++dTh5xjK0DoX/LhGtcEhEMcJETCkKsOihh4vX4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.17.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1595339},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"c478cd2fdc8c39e481d4e40352174c185687c29b","scripts":{"dev":"vite","a11y":"npm run browser --","demo":"tsx scripts/demo.ts","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts --mode embed && vite build --config vite.embed.config.ts --mode dpp-verifier","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","terser":"^5.51.2","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.17.1_1789623073805_0.7740986496912847","host":"s3://npm-registry-packages-npm-production"}},"2.18.0":{"name":"transpareo-time-machine","version":"2.18.0","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","_id":"transpareo-time-machine@2.18.0","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"homepage":"https://github.com/transpareo/transpareo-time-machine","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"aab3e86d1642e26c70aedae8922e722ee0dc8c2a","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.18.0.tgz","fileCount":94,"integrity":"sha512-TPQhQeU5xeWyhq7EXhHWI1yjBHhZJkqulkMivIW10t7kasI55XnUF1xnId+g3t1+zDcWFw8Blh51/pX/KubLXQ==","signatures":[{"sig":"MEUCIQCOuH1GcJJ/lIpMc6aN4gMUywYpSeASGfpvnDogpkK5bQIgcBRc+L2Mpl2Dwqtckv9iguAENyrdR1o3gFNtbCQAnGI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIC2J/2vjVwnYrSCDnUHxzBegB2+0QXvpelNWVv+S+pGKAiEA9wO5Z2iWZrYETLn2gtOAP+mj6eF8Nxnrzti6P4wpLDU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.18.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1598492},"main":"./dist/transpareo-time-machine.js","type":"module","types":"./types/index.d.ts","module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"86f29fe69d5613e8bb3fa3df36c072b4d401e2e5","scripts":{"dev":"vite","a11y":"npm run browser --","demo":"tsx scripts/demo.ts","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts --mode embed && vite build --config vite.embed.config.ts --mode dpp-verifier","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","terser":"^5.51.2","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"tmp":"tmp/transpareo-time-machine_2.18.0_1789673704450_0.806128274768968","host":"s3://npm-registry-packages-npm-production"}},"2.18.1":{"_id":"transpareo-time-machine@2.18.1","bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"dist":{"shasum":"8a23945fc10c2aacc88788f9d9c18eea9bc9b891","tarball":"https://registry.npmjs.org/transpareo-time-machine/-/transpareo-time-machine-2.18.1.tgz","fileCount":94,"integrity":"sha512-PIKc5v0H5Ae7TR+RW5xCXGIQEQW+l5KJaAGN9YY5z7OctcxVcNM14CEzwE7yEzK+5SED+JLAyjsdPeZJ+OIHsQ==","signatures":[{"sig":"MEQCIEApACC25ijxy9vX5LF0h6BgZBxihJoW6/WhHhDd/qg4AiBJ4nJcmoP7GkEqayNQZzNt3Xbsx5PD9KNaLTZqfOnXww==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBOi8QDRIPBajjryggSvzZUG12Kk+OzOnW71PKziEvKtAiBVS70TBYQvpjKlV27zbU5c12G7equxTgHrgxax2pQg3Q=="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/transpareo-time-machine@2.18.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1604215},"main":"./dist/transpareo-time-machine.js","name":"transpareo-time-machine","type":"module","types":"./types/index.d.ts","author":{"name":"Transpareo AG"},"module":"./dist/transpareo-time-machine.js","engines":{"node":">=22"},"exports":{".":{"types":"./types/index.d.ts","import":"./dist/transpareo-time-machine.js","default":"./dist/transpareo-time-machine.js"},"./embed":{"types":"./types/embed.d.ts","import":"./dist-embed/embed.js","default":"./dist-embed/embed.js"},"./style.css":"./dist/transpareo-time-machine.css","./dpp-verifier":{"types":"./types/dpp-verifier.d.ts","import":"./dist/dpp-verifier.js","default":"./dist/dpp-verifier.js"},"./package.json":"./package.json"},"gitHead":"79bf25f320b9fd63d124a34ee78af5c878c51aab","license":"GPL-3.0-or-later","scripts":{"dev":"vite","a11y":"npm run browser --","demo":"tsx scripts/demo.ts","lint":"eslint .","seed":"./scripts/seed.sh","test":"vitest run","build":"vite build","check":"tsc --noEmit -p tsconfig.app.json && tsc -p tsconfig.node.json && tsc -p tsconfig.tests.json","browser":"playwright test --project=chromium","prepack":"npm run build:all","preview":"vite preview","release":"./scripts/release.sh","emit:sri":"tsx scripts/emit-sri.ts","build:all":"npm run build && npm run build:embed","dev:nordic":"SEED=nordic-wear-tshirt vite","test:watch":"vitest","build:embed":"vite build --config vite.embed.config.ts --mode embed && vite build --config vite.embed.config.ts --mode dpp-verifier","serve:embed":"tsx scripts/serve-embed.ts","dev:volturra":"SEED=volturra-pulse-2000 vite","browser:webkit":"playwright test --project=webkit","check:fixtures":"tsx scripts/seed/validate.ts","browser:firefox":"playwright test --project=firefox","check:bundle-size":"tsx scripts/check-bundle-size.ts","check:reproducible":"bash scripts/check-reproducible.sh","browser:webkit:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:webkit","browser:firefox:docker":"docker run --rm --user $(id -u):$(id -g) -e HOME=/tmp -e npm_config_cache=/tmp/.npm -v \"$PWD\":/w -w /w mcr.microsoft.com/playwright:v$(node -p \"require('@playwright/test/package.json').version\")-noble npm run browser:firefox"},"version":"2.18.1","_npmUser":{"name":"punkrats","email":"andre.pankratz@transpareo.com"},"homepage":"https://github.com/transpareo/transpareo-time-machine","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"_npmVersion":"10.9.8","description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","directories":{},"maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","zod":"^4.4.3","sass":"^1.99.0","vite":"^8.0.10","yaml":"^2.9.0","eslint":"^10.4.0","terser":"^5.51.2","vitest":"^4.1.6","happy-dom":"^20.10.2","@eslint/js":"^10.0.1","typescript":"~6.0.2","@types/node":"^24.12.2","@playwright/test":"^1.60.0","typescript-eslint":"^8.59.4","@axe-core/playwright":"^4.11.3"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/transpareo-time-machine_2.18.1_1790016628597_0.6790804813803852"}}},"time":{"created":"2026-06-03T14:04:16.614Z","modified":"2026-09-21T18:50:29.019Z","0.0.0":"2026-06-03T14:04:16.903Z","1.0.0":"2026-06-17T15:03:32.382Z","2.0.0":"2026-06-20T16:12:01.466Z","2.0.1":"2026-06-23T05:10:07.481Z","2.1.0":"2026-06-25T12:17:24.117Z","2.2.0":"2026-06-28T10:57:26.641Z","2.3.0":"2026-07-02T15:25:55.690Z","2.4.0":"2026-07-02T19:07:58.521Z","2.5.0":"2026-07-24T07:12:16.249Z","2.5.1":"2026-07-24T13:58:36.526Z","2.5.2":"2026-07-25T06:36:34.174Z","2.6.0":"2026-07-31T13:58:38.062Z","2.7.0":"2026-08-08T16:31:12.796Z","2.8.0":"2026-08-09T10:34:49.076Z","2.8.1":"2026-08-12T08:59:05.401Z","2.9.0":"2026-08-12T15:07:33.149Z","2.10.0":"2026-08-18T21:52:37.644Z","2.11.0":"2026-08-19T04:57:00.242Z","2.12.0":"2026-08-19T21:14:39.712Z","2.12.1":"2026-08-19T23:00:32.578Z","2.12.2":"2026-08-19T23:39:02.839Z","2.13.0":"2026-08-20T06:19:57.310Z","2.14.0":"2026-08-21T02:51:38.737Z","2.14.1":"2026-08-21T03:46:49.028Z","2.14.2":"2026-09-11T10:22:51.935Z","2.15.0":"2026-09-12T00:23:13.434Z","2.16.0":"2026-09-14T01:03:56.689Z","2.16.1":"2026-09-14T03:36:27.480Z","2.17.1":"2026-09-17T05:31:13.950Z","2.18.0":"2026-09-17T19:35:04.564Z","2.18.1":"2026-09-21T18:50:28.700Z"},"bugs":{"url":"https://github.com/transpareo/transpareo-time-machine/issues"},"author":{"name":"Transpareo AG"},"license":"GPL-3.0-or-later","homepage":"https://github.com/transpareo/transpareo-time-machine","keywords":["dpp","digital-product-passport","epcis","esprr","renderer","spa"],"repository":{"url":"git+https://github.com/transpareo/transpareo-time-machine.git","type":"git"},"description":"Open-source Digital Product Passport renderer: a self-contained SPA that consumes signed DPP snapshots + EPCIS events and renders the public passport page for a publisher.","maintainers":[{"name":"punkrats","email":"andre.pankratz@transpareo.com"}],"readme":"# Transpareo Time Machine\n\n[![ci](https://github.com/transpareo/transpareo-time-machine/actions/workflows/ci.yml/badge.svg)](https://github.com/transpareo/transpareo-time-machine/actions/workflows/ci.yml)\n[![npm](https://img.shields.io/npm/v/transpareo-time-machine?label=npm)](https://www.npmjs.com/package/transpareo-time-machine)\n[![licence](https://img.shields.io/npm/l/transpareo-time-machine?label=licence)](LICENSE)\n\nOpen-source Digital Product Passport renderer.\n\nThe Transpareo Time Machine is a single-page app (SPA)\nyou embed as one custom element. Point it at a Digital\nProduct Passport and it renders an interactive card:\nthe product's current details up front, and a timeline\nthe visitor can scrub back through to replay every\nearlier version the passport has had. A verification\nchip on the card shows whether the data is authentic,\nchecked cryptographically in the visitor's own browser\ninstead of taken on trust from a server.\n\n![The renderer showing a Nordic Wear t-shirt passport: the timeline opens and fans out every event in the product's history, the recall event's record opens down to its raw EPCIS fields, and the card scrubs back to the launch version before returning to today](docs/demo.webp)\n\n**Demo:**\n[time-machine.transpareo.com](https://time-machine.transpareo.com)\nrenders three sample passports end to end: a Nordic Wear\nt-shirt (signed with `eddsa-jcs-2022`, minimally themed),\na Volturra Pulse 2000 (signed with the `ecdsa-sd-2023`\nselective-disclosure suite, aggressively themed - the two\ntogether showcase how far the branding tokens stretch),\nand an Atelier Barro vase, an unsigned single-snapshot\npassport with no manifest, showing how the renderer\npresents a bare foreign DPP with no verification chrome\nor custom styling. Scrub the timeline and watch the\nverification chip in action on both proof types.\n\nEmbedding it is one custom-element tag. The simplest\n`src` is the passport URL itself - the URL the QR code\non the product resolves to, here in its minimal\nstandardised form, a GS1 Digital Link carrying just\nthe 14-digit GTIN:\n\n```html\n<transpareo-time-machine\n  src=\"https://example.com/01/09524000059109\">\n</transpareo-time-machine>\n```\n\nThat is just an example - any DPP URL works. The\nEuropean DPP standards require a passport URL to\nanswer with the JSON dataset when a client asks for\nJSON via HTTP content negotiation (the EN 18216\nbaseline), and the renderer asks exactly that way: it\nrequests its `src` with\n`Accept: application/ld+json, application/json`.\nFrom the single dataset such a URL returns, the\nTranspareo Time Machine renders in single-snapshot\nmode: the current version with its verification\nchip, no timeline - one document carries no history.\n\nThe ***full*** Time Machine - the timeline a visitor scrubs\nback through, per-version verification, the hash\nchain binding each version to its predecessor - needs\na version index, and the standards do not provide\none: EN 18221 obliges publishers to archive every\nversion, but the standardised API reaches the archive\none date-query at a time (`ReadDPPVersionByIdAndDate`,\noptional for the operator) and has no method that\nlists versions. The manifest is this package's\nconvention for exactly that gap: one signed document\nnaming every version with its URL, hash, and date.\nPoint `src` at it and the timeline lights up:\n\n```html\n<transpareo-time-machine\n  src=\"https://example.com/01/09524000059109/manifest.json\">\n</transpareo-time-machine>\n```\n\nThe manifest can live anywhere you can serve a URL.\nThe renderer assumes nothing about where or how you\nhost: it reads each artefact's address from the\nmanifest (relative URLs resolve against the\nmanifest's own URL), so you publish wherever you\nlike. Its structure is documented in \"The manifest\"\nbelow.\n\nLicense: [GPL-3.0-or-later](LICENSE).\n\n## Why this exists\n\nMost DPP renderers in 2026 either (a) trust an\nissuer-controlled server's \"verified\" flag and re-render\nit as a static UI, or (b) verify against a single\nauthority and surrender the result to the issuer's\ninfrastructure to display. The Transpareo Time Machine\ninstead:\n\n- Computes the verification verdict **client-side**,\n  in the visitor's browser, from the signed snapshot's\n  embedded `eddsa-jcs-2022` proof set, never from a\n  server's \"verified\" flag. How much that verdict is\n  worth depends on the surface it runs on. On a renderer\n  the visitor trusts (e.g. the standalone verifier page)\n  with a platform key pinned via `pinned-platform-key` /\n  `config.pinnedPlatformKeys`, a compromised *data* origin\n  cannot forge it. On a page the issuer fully controls,\n  the chip is advisory: that page could paint its own\n  badge or skip the renderer entirely, so the embedded\n  chip is a convenience there, not a guarantee.\n- Treats the issuer and the platform as **two\n  independent authorities**. The default\n  \"any-issuer-and-any-platform\" verdict groups proof\n  entries by signature and requires one verified entry\n  per group; it does not, on its own, bind the platform\n  side to a particular key. Pin a platform key to bind\n  it, or use strict all-entries mode for high-trust\n  surfaces.\n- Ships **zero runtime dependencies**. The reactive\n  runtime, the JCS canonicalizer, the multibase\n  decoder, and the in-browser verifier are all\n  vendored under `src/` and total under 4000 lines.\n- Embeds as a **single custom element** with one\n  attribute (`src`). No build step required for the\n  host page; see \"Using it in a host page\" below.\n\nIf your project does need a different model (e.g.\nDID-based authority discovery, X.509 cert chains,\nissuer-hosted verification), the Transpareo Time Machine\nis probably not the right fit. Forks are welcome.\n\n## The manifest\n\nThe manifest is the version index of a passport: one\nsigned JSON document listing every published version,\nso a client can enumerate the history that the\nstandardised DPP APIs otherwise expose only one\ndate-query at a time. Everything else the renderer\ntouches is named by it - each version's snapshot at\n`versions[].url`, the events document at `epcisUrl` -\nso the renderer never assumes a path layout in your\nbucket. A trimmed real manifest:\n\n```json\n{\n  \"@context\": [\n    \"https://www.w3.org/ns/credentials/v2\",\n    \"https://transpareo.com/contexts/dpp/v1\"\n  ],\n  \"@type\": \"DppManifest\",\n  \"code\": \"demo-2026-t001\",\n  \"issuer\": {\n    \"@type\": \"Organization\",\n    \"name\": \"Nordic Wear\",\n    \"did\": \"did:web:nordic-wear.example\"\n  },\n  \"platform\": {\n    \"@type\": \"Organization\",\n    \"name\": \"Transpareo\",\n    \"did\": \"did:web:transpareo.example\"\n  },\n  \"availableLocales\": [\"en\", \"de\", \"fr\"],\n  \"currentVersion\": 6,\n  \"versions\": [\n    {\n      \"number\": 1,\n      \"publishedAt\": \"2024-01-15T10:00:00Z\",\n      \"reason\": \"Initial publication\",\n      \"hashValue\": \"5a52500ff539...\",\n      \"url\": \"v/1.json\",\n      \"sizeBytes\": 10812\n    },\n    {\n      \"number\": 6,\n      \"publishedAt\": \"2026-04-05T13:45:00Z\",\n      \"reason\": \"Repair documented\",\n      \"hashValue\": \"dc65871414b2...\",\n      \"url\": \"v/6.json\",\n      \"sizeBytes\": 11943,\n      \"privateProperties\": {\n        \"url\": \"https://api.nordic-wear.example/dpps/demo-2026-t001/private_properties/6\"\n      }\n    }\n  ],\n  \"epcisUrl\": \"epcis.json\",\n  \"signedAt\": \"2026-04-05T13:45:00Z\",\n  \"signature\": {\n    \"type\": \"DataIntegrityProof\",\n    \"cryptosuite\": \"eddsa-jcs-2022\",\n    \"created\": \"2026-04-05T13:45:00Z\",\n    \"verificationMethod\": \"keys/platform.json\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"proofValue\": \"z5owR9zthjFC...\"\n  }\n}\n```\n\nField notes:\n\n- `versions[]` - one entry per published version.\n  `url` points at the version's signed snapshot;\n  relative URLs resolve against the manifest's own\n  URL. `hashValue` (with optional `hashAlgorithm` /\n  `hashCanonicalForm`) is the snapshot's content\n  hash; the next version's snapshot names it as\n  `priorVersionHash`, the chain check that binds the\n  history together. `publishedAt` anchors the\n  version's timeline dot, `reason` is the\n  human-readable change label, `sizeBytes` the\n  snapshot's size on the wire.\n- `currentVersion` - the version rendered on first\n  paint; the timeline scrubs backward from there.\n- `versions[].privateProperties.url` (optional) - a\n  publisher-hosted endpoint returning the login-gated\n  property rows the current user may read. Present\n  only on versions carrying such rows. When it is,\n  the renderer fetches it anonymously and branches on\n  the status: 200 merges the returned rows, 401\n  surfaces a sign-in button that hands off to the\n  publisher's own login page. That hand-off carries\n  `return=` (where to come back to) and `locale=` (the\n  language the visitor is reading the passport in, as\n  the passport declares it). A login URL that already\n  names a locale is passed through untouched, which is\n  how an issuer opts out.\n- `versions[].registeredAt` / `registrationProof`\n  (optional) - EU-registry round-trip metadata,\n  surfaced in the proof modal when present.\n- `availableLocales` - the locales this passport is\n  published in; drives the footer language picker.\n- `epcisUrl` - the EPCIS 2.0 events document the\n  event timeline derives from.\n- `issuer` / `platform` - schema.org-style\n  attribution blocks; their `did` identities are\n  matched against the snapshot proof entries.\n- `voidedAt` / `voidedReason` / `supersededBy`\n  (optional) - the passport is out of circulation.\n  In a versioned publication only the manifest can say\n  so: a snapshot is signed once and frozen, so the one\n  on screen was written while the passport still stood,\n  and the manifest is re-signed on every change. A DPP\n  served as a lone document carries the same three keys\n  on the document itself, and the renderer reads them\n  there when it booted without a manifest. The renderer states it in\n  a band across the top of the card, over every\n  version, since the unit is out of circulation today\n  whichever version is being read. `voidedReason` is a\n  token, not a phrase (`recalled`, `destroyed`,\n  `never_shipped`, `other`); a token this renderer does\n  not know reads as `other`. `supersededBy` names the\n  replacement passport by `code` (plus an optional\n  `uuid`), which the band prints, and optionally by\n  `url`, the successor's public passport page, which\n  the band links the code to. A manifest published\n  before the publisher emitted addresses carries no\n  `url`, and the code then renders as plain text\n  rather than as a guess at where to find it:\n\n  ```json\n  \"voidedAt\": \"2026-09-13T21:42:31Z\",\n  \"voidedReason\": \"recalled\",\n  \"supersededBy\": {\n    \"code\": \"demo-2026-t002\",\n    \"url\": \"https://example.com/01/09524000059116\"\n  }\n  ```\n\n- `signature` - a W3C Data Integrity proof\n  (`eddsa-jcs-2022`, platform key) over the manifest\n  body. The renderer verifies it and folds the\n  outcome into every version verdict, so a tampered\n  version list cannot present itself as verified. It\n  covers the withdrawal fields above like any other.\n\n## Using it in a host page\n\nThree supported integration modes. Pick the one that\nmatches your stack:\n\n### 1. CDN (`<script>` tag, no build step)\n\nThe npm package is mirrored at unpkg and jsdelivr at\nversioned URLs. For drop-in script-tag use, load the\n**embed bundle** - one URL, stylesheet inlined, no\nordering risk:\n\n```html\n<script type=\"module\"\n        src=\"https://unpkg.com/transpareo-time-machine@2.18.1/dist-embed/embed.js\"></script>\n\n<transpareo-time-machine\n  src=\"https://cdn.example.com/acme/01/09524000059109/manifest.json\">\n</transpareo-time-machine>\n```\n\nPin a specific version (`@2.18.1`) for production. Use\n`@latest` only in throwaway demos.\n\nThe embed bundle inlines `app.css` into a `<style>` it\ninjects at module init, so you do **not** need a\nseparate `<link rel=\"stylesheet\">`. The renderer's\nfunctional icons (controls, status) are bundled inline\nand always render. The decorative content icons are\noptional: host a sprite (`icons-src`) plus a\n`propertyID`-to-icon map (`icon-map-src`); the package\nships neither (see \"Icons\"):\n\n```html\n<transpareo-time-machine\n  src=\"https://cdn.example.com/acme/01/09524000059109/manifest.json\"\n  icons-src=\"https://cdn.example.com/acme/icons.svg\">\n</transpareo-time-machine>\n```\n\nIf you are pulling the bundle into a host that already\nmanages its own CSS pipeline (and would rather keep the\nstylesheet as a separate, fingerprint-able asset), load\nthe lib bundle instead:\n\n```html\n<link rel=\"stylesheet\"\n      href=\"https://unpkg.com/transpareo-time-machine@2.18.1/dist/transpareo-time-machine.css\">\n<script type=\"module\"\n        src=\"https://unpkg.com/transpareo-time-machine@2.18.1\"></script>\n```\n\nLib vs embed is a CSS-delivery choice; both expose the\nsame `<transpareo-time-machine>` element with identical\nbehaviour.\n\nThe renderer learns the hero image URL from the snapshot,\nso on its own it can only request it once the bundle has\nparsed, the manifest is in and the first snapshot has\nfollowed. A host page that knows the current version's\nfirst gallery thumbnail can hand it to the browser up\nfront, and the largest paint starts at the first round\ntrip instead of the fifth:\n\n```html\n<link rel=\"preload\" as=\"image\" fetchpriority=\"high\"\n      href=\"https://cdn.example.com/acme/media/hero-800.jpg\">\n```\n\nPreload the URL the renderer will actually request. A\nsnapshot states its image references relatively and they\nresolve against the snapshot's own URL, so a `thumbnail`\nof `/media/hero-800.jpg` in a snapshot served from\n`https://cdn.example.com/acme/dpp/...` is requested as\n`https://cdn.example.com/media/hero-800.jpg`. A preload\nnaming any other host is a second copy of the image\nrather than a head start.\n\nAn image may name more than one rendition of itself. Each\nentry in a snapshot's `images` can carry a `variants`\narray, every rendition the publisher holds with its\nintrinsic width in pixels:\n\n```json\n{\n  \"thumbnail\": \"/media/hero-800.jpg\",\n  \"large\": \"/media/hero-1500.jpg\",\n  \"variants\": [\n    { \"url\": \"/media/hero-400.jpg\", \"width\": 400 },\n    { \"url\": \"/media/hero-800.jpg\", \"width\": 800 },\n    { \"url\": \"/media/hero-1500.jpg\", \"width\": 1500 }\n  ]\n}\n```\n\nThe renderer turns that into a `srcset` on the hero image,\npaired with a `sizes` describing the box the hero actually\nfills: `(max-width: 600px) calc(100vw - 50px), 320px`, a\nfixed column beside the product copy, and the viewport\nless the card's padding once the card stacks. A rendition\nmissing a URL or a positive width is skipped, and a list\nthat comes down to a single rendition is dropped, since\n`src` already says that much. A snapshot naming no\nvariants renders from `thumbnail` alone, as every snapshot\ndid before.\n\nEmit a ladder rather than the two ends. A 360px-wide hero\non a 2x phone wants around 720px of image, so a set of\n400, 600, 800 and 1200 lets the browser land near what it\nneeds; with only 400 and 1500 to choose from it takes\n1500.\n\nOnce an image carries renditions the browser picks by\nwidth and density instead of taking `src`, and a preload\nnaming one URL no longer matches that pick. Restate the\nlist on the preload so it still does:\n\n```html\n<link\n  rel=\"preload\"\n  as=\"image\"\n  fetchpriority=\"high\"\n  href=\"https://cdn.example.com/media/hero-800.jpg\"\n  imagesrcset=\"https://cdn.example.com/media/hero-400.jpg 400w,\n               https://cdn.example.com/media/hero-800.jpg 800w\"\n  imagesizes=\"(max-width: 600px) calc(100vw - 50px), 320px\">\n```\n\nThe manifest cannot be preloaded. The renderer fetches\nit with `cache: 'no-cache'`, because it is the trust\nanchor for the whole version list and carries the\nwithdrawal state; a request that refuses the HTTP cache\nis never served from the preload cache, so a preload\nlink downloads the bytes a second time and the browser\nfetches them again anyway. Measured on a real passport\npage, cold and warm: the preload transfers the manifest\nand the renderer's own request still goes to the network\nfor it every time. Small bytes (a manifest is around\nhalf a kilobyte on the wire), but a wasted request on\nthe critical path, where it competes with the artefacts\nthe first paint is actually waiting for.\n\nWhat does pay, for a shell that renders per passport and\ntherefore knows the addresses:\n\n```html\n<link rel=\"preconnect\" href=\"https://cdn.example.com\" crossorigin>\n<link rel=\"preload\" as=\"fetch\" crossorigin\n      href=\"https://cdn.example.com/dpp/<code>/v/6.json\">\n```\n\nThe preconnect opens the connection the boot fetch needs\nbefore the bundle has parsed. The current version's\nsnapshot is fetched with ordinary caching, so that one\npreload is reused (2ms in the same measurement) rather\nthan doubled. Hand-written pages should skip the snapshot\npreload: its URL changes with every publish, and a stale\none preloads bytes the renderer will not ask for.\n\n### 2. npm + a bundler (Vite, Next, webpack, etc.)\n\n```bash\nnpm install transpareo-time-machine\n```\n\n```ts\n// In your app's entry:\nimport 'transpareo-time-machine';\nimport 'transpareo-time-machine/style.css';\n```\n\nThen drop the element anywhere in your markup. The\npackage ships no icon sprite; the functional icons are\ninline. For the decorative content icons, host your own\nsprite (`icons-src`) and `propertyID`-to-icon map\n(`icon-map-src`) (see \"Icons\").\n\nFor the standalone verifier-only widget (no Time\nMachine SPA), import the secondary entry:\n\n```ts\nimport 'transpareo-time-machine/dpp-verifier';\n```\n\n```html\n<dpp-verifier></dpp-verifier>\n```\n\nIf your bundler integration is more \"drop a script tag\ninto the output\" than \"fully integrate the asset\ngraph\" - e.g. you ship a server-rendered page and\nmanage CSS by hand - the `./embed` entry is also\nexported:\n\n```ts\nimport 'transpareo-time-machine/embed';\n```\n\n…which inlines `app.css` instead of pulling it as a\nsibling import, so you don't need the\n`'transpareo-time-machine/style.css'` line above.\n\n### 3. Self-hosted bundle\n\nIf you want zero third-party runtime dependencies, build\nonce and host the artefacts on your own infrastructure:\n\n```bash\ngit clone https://github.com/transpareo/transpareo-time-machine.git\ncd transpareo-time-machine\nnpm install\nnpm run build:all\n# Lib delivery (separate JS + CSS, bundler-friendly):\n#   dist/transpareo-time-machine.{js,css}\n#   dist/dpp-verifier.{js,css}\n#   dist/locales/<lc>.js          (lazy locale chunks;\n#                                  English is in the main file)\n#\n# Embed delivery (one JS file, CSS inlined, script-tag\n# friendly):\n#   dist-embed/embed.js\n#   dist-embed/<lc>.js            (lazy locale chunks;\n#                                  English is in the main file)\n#\n# Copy whichever delivery matches your host's CSS\n# pipeline to your static host. The lib delivery\n# matches the unpkg snippet in section 1's second\n# block; the embed delivery matches the first block.\n```\n\nThe build is reproducible from source; no network calls\nat runtime beyond fetching the DPP artefacts themselves.\n\n### Content Security Policy on the host page\n\nA page that sets a CSP has to allow what verification\nreads, and one of those hosts is not visible anywhere in\nthe page's own markup: a proof names its key by\n`verificationMethod`, and the renderer resolves that to\nwhatever host the artefact points at. A key the page\ncannot fetch is a key its proof cannot be judged under,\nso once every alias of an authority sits on a blocked\nhost, the chip reads \"Verification failed\" rather than\nanything about a blocked request. The browser logs the\nreal cause as a CSP report.\n\n`connect-src` needs:\n\n- the origin serving the manifest, the snapshots and the\n  EPCIS events, wherever `src` points;\n- **every host a `verificationMethod` resolves to** - the\n  issuer's key host and the platform's, including the\n  `did:web` hosts, which resolve to\n  `https://<host>/.well-known/did.json`. Read them off a\n  snapshot's `proof[].verificationMethod`;\n- the revocation endpoint when the page pins a platform\n  key: `https://transpareo.com` by default, or whatever\n  `revoked-roots-src` names (`revoked-roots-src=\"\"`\n  disables the check and the fetch with it);\n- the hosts serving `icons-src` and `icon-map-src`, when\n  those are set.\n\nThe rest follows the assets a passport renders with:\n`img-src` for product imagery and the brandbar logo,\n`style-src` and `font-src` for the publisher's branding\nstylesheet and the typeface it declares, `script-src` for\nwherever the bundle is served from.\n\nA passport page needs no sockets and no payment SDK, so a\npolicy inherited from a wider application is usually both\ntoo permissive in what it grants and too narrow where it\ncounts. The example policy in `embed-example.html` is\ndeliberately loose (`connect-src 'self' https:`); tighten\nit host by host, and keep the key hosts in.\n\n## Public API\n\nThe package ships two custom elements; both register\nthemselves on import as a side effect, so host pages\nnever call `customElements.define` directly.\n\nTypeScript declarations ship with the package\n(hand-written in `types/`, since the entries export no\nruntime symbols): the tag names are registered in\n`HTMLElementTagNameMap` so `querySelector` /\n`createElement` return the typed elements, the\n`transpareo-time-machine:state` event detail is typed via\n`HTMLElementEventMap`, and the `openModal` options/handle\ntypes are importable from the package root.\n\n### `<transpareo-time-machine>`\n\nThe full passport renderer.\n\n| Attribute | Required | Effect |\n|-----------|----------|--------|\n| `src` | yes | URL of the DPP manifest, of a single signed snapshot, or the passport URL of a publisher that serves JSON via content negotiation. Resolved against `document.location` if relative. Changing the attribute live triggers a re-fetch. |\n\n| Surface | Notes |\n|---------|-------|\n| Events | `transpareo-time-machine:state` (see \"Integration hook\" below). |\n| Slots | `additional` (see \"Integration hook\" below). |\n| Methods | `openModal({ title, body, onClose? }) -> { close }` (see \"Integration hook\" below). |\n| Properties | `state` (read-only): the same detail the `:state` event carries, or `null` before the manifest has loaded. |\n| CSS parts | None today. The element has an open shadow root, so host pages can reach inner DOM via `::shadow`-style selectors but doing so is unsupported and may break on any release. |\n| CSS custom properties | The publisher theming surface (see \"Theming\" below). Custom properties inherit through the shadow boundary, so any `--token` set on the host page applies inside. |\n| Attributes | `src` (DPP **manifest** URL, or a single signed **snapshot** URL; see \"Single-snapshot mode\" below), `icons-src` (decorative content sprite), `icon-map-src` (per-publisher JSON mapping each property's `propertyID` to a sprite symbol id; pairs with `icons-src`), `revoked-roots-src` (revocation endpoint; `''` disables the boot check), `show-verification-mark` (`false` always hides the verification chip, `true` always shows it; absent, the chip hides itself for a lone snapshot that carries no proof), `pinned-platform-key` (whitespace-separated Multikey set; the chip must see one of them among the verified entries; also keys the revoked-roots check), `pinned-issuer-key` (whitespace-separated Multikey set of the issuer's declared signing keys - under BYOK the customer's own registered keys; the chip requires a verified issuer entry under one of them), `verifier` (present: mount `<dpp-verifier>` in place of the renderer), `logo-href` (where the brandbar logo links to, typically the publisher's home page; absent, the logo stays plain artwork), `footer-copyright` + `footer-links` (footer chrome; `footer-links` is a JSON array of `{ label, url }`). Read once in the element's `setup()` (`src/config.ts`). `locale` states which language to render in: a tag (`locale=\"de\"`), `inherit` to follow the language surrounding the element, or `auto` (the default, and what an absent attribute means) to detect from the visitor's browser. It outranks the standard `lang` attribute, which is still read where no `locale` is given, so `locale=\"auto\"` is how a page that templates `lang` everywhere keeps detection. Either pins the UI locale ahead of the browser preference and of a locale the visitor picked on another page; see \"Localization\" below. |\n\n#### The verification mark\n\nThe chip in the brandbar surfaces the active version's\nverification state and opens the proof modal on click.\nIts states: a spinner while proofs verify, \"Verified by\n<name>\" (or the neutral \"Verified\" when no platform name\nis earned), \"Verification failed\", \"Not yet published\"\n(an unsigned draft; inert, no modal), and the muted\nquestion mark \"Not verifiable\" - nothing was judged\neither way, because the snapshot carries no proof or its\nproof names a cryptosuite this build does not ship; the\nmodal states which.\n\n`show-verification-mark` controls whether the chip\nrenders at all:\n\n| Value | Behaviour |\n|---|---|\n| absent | Auto. The chip shows, except for a lone snapshot carrying no proof: a DPP that never claimed verifiability is not badged for lacking it, so the renderer stays a neutral viewer for unsigned passports. Under a manifest the chip always shows, since a missing snapshot proof there means a signed publication was stripped, and the question mark must surface that. |\n| `\"true\"` | Always show, including the question mark on an unsigned lone snapshot. |\n| `\"false\"` | Never show. |\n\nWhen neither the chip nor a themed logo (`--logo-url`)\nrenders, the brandbar is omitted entirely rather than\nleft as an empty sticky header, and the card content\nkeeps a padded top edge (1.5x its vertical padding) in\nits place.\n\nThe logo is plain artwork unless `logo-href` names a\ndestination, typically the publisher's own home page; with\nit, the logo renders as a link there. Only a logo the theme\nactually supplies is linked, so a chip-only bar gains no\ninvisible click target, and the URL passes the same scheme\nguard as the footer links: a `javascript:` value leaves the\nlogo unlinked rather than armed. The artwork carries no\ntext, so the link takes a localized accessible name\n(\"Home page\") instead of announcing its own URL.\n\n#### Single-snapshot mode\n\n`src` may point at a single signed snapshot instead of a\nmanifest. This is also what a passport URL resolves to when\nthe publisher serves JSON via content negotiation: every\nartefact fetch carries\n`Accept: application/ld+json, application/json`, and the\ndataset such a URL returns is one snapshot, the passport's\ncurrent version. The element detects which shape it was\ngiven; for a lone snapshot it renders that one frozen\nversion with no version timeline, history, or EPCIS events\n(a snapshot carries no version list), and the language\npicker is derived from the snapshot's own localized\nstrings. The snapshot's own 2-of-2\nproof still verifies, so the chip reads \"verified\" on a\nvalidly-signed snapshot. This is a weaker assurance than the\nmanifest flow: with no signed version list and no\ncross-version chain, it proves the snapshot is authentic,\nnot that it is the current version of a history.\n\nA snapshot that carries no proof at all is not treated as\na failed verification - there is nothing to judge either\nway. By default such a lone snapshot renders with no\nverification chrome; \"The verification mark\" above has\nthe full policy and the `show-verification-mark`\noverrides. Where the chip does render, it shows the\nmuted question mark straight from the data, with no\nverifying phase, and its modal explains that no\nverification is possible, naming the cryptosuite when an\nunshipped proof format is the cause. The\nstandalone `<dpp-verifier>` widget agrees on all of it:\nmanifest-or-snapshot detection is one shared rule\n(`src/artefact-detect.ts`), a pasted snapshot URL is\njudged on its own proof set (the identity tier stays at\n\"signer identity unconfirmed\" without a manifest to bind\na name to, unless a pinned key matches), and an unsigned\nor unreadable one gets the same neutral notice instead of\na red failure card.\n\n#### Integration hook\n\nThe renderer exposes one named slot, one custom event,\none property, and one method so a host page can drop in\nextras (a leadgen CTA, a recall banner, a regional\ndisclosure, ...) without coupling to the SPA's\ninternals or forking the bundle.\n\n- **Slot**: `slot=\"additional\"`. Renders at a stable\n  position inside the card, directly above the\n  composition donut. Light-DOM children of\n  `<transpareo-time-machine>` with that `slot`\n  attribute are projected into it. More than one such\n  child is supported, projected in light-DOM source\n  order, so independent integrations can each slot\n  their own CTA without composing a shared wrapper.\n  Branding CSS custom properties (the `--color-*` and\n  `--font-*` tokens) cascade through the slot boundary,\n  so a slotted button inherits the publisher's theme\n  without extra wiring. An element with no children or no\n  `slot=\"additional\"` child renders nothing extra; the\n  SPA fetches nothing on the integration's behalf.\n  The slot is hidden while the visitor scrubs to a\n  historical version and reappears when they return\n  to the current version. The integration's slotted\n  child stays attached the whole time; the SPA just\n  stops projecting it during historical view. This\n  is deliberate: marketing CTAs, recall banners, and\n  similar extras apply to the live product, not to\n  the regulatory record being scrubbed.\n- **Event**: `transpareo-time-machine:state`. Fires\n  on the host element (does not bubble) once the SPA\n  is ready, and again on every timeline step, locale\n  switch, and manifest change:\n\n  ```ts\n  tm.addEventListener('transpareo-time-machine:state', (e) => {\n    const { code, locale, version, currentVersion, manifestUrl } = e.detail\n    // ...fetch your config, build a slotted child, attach it...\n  })\n  ```\n\n  The detail is intentionally identity-only, no\n  snapshot content. The SPA never inspects the slot's\n  content or the integration's network calls.\n\n  The event is a \"here is the current identity\"\n  signal, not a change notification: it re-dispatches\n  on every timeline step, including steps between two\n  events that resolve to the same version number, so\n  the detail is often identical to the previous one.\n  Every handler must be idempotent. Note also that a\n  URL hash is a deep link to a historical version, so\n  for those loads the very first dispatch already\n  carries `version !== currentVersion` and the slot\n  starts hidden; an integration that opens a modal by\n  itself should gate on `version === currentVersion`.\n  The event has no replay, so an integration script\n  that attaches its listener after the initial\n  `'ready'` dispatch would otherwise wait for the next\n  state change to learn anything. Read `tm.state` once\n  when attaching the listener and follow the event from\n  there; it returns the same detail, or `null` if the\n  manifest has not loaded yet, in which case the first\n  dispatch is still to come.\n- **Property**: `tm.state`, read-only. The same detail\n  the event carries, or `null` before the manifest has\n  loaded. It is a live read, not a copy of the last\n  dispatch, so it is also the way to answer \"is the\n  visitor on the current version right now\" outside a\n  listener:\n\n  ```ts\n  const s = tm.state\n  if (s && s.version === s.currentVersion) {\n    // ...safe to show a CTA or open a modal\n  }\n  ```\n- **Method**: `tm.openModal({ title, body, onClose? })`.\n  Opens a modal styled with the same chrome as the\n  SPA's own modals (overlay, header with close button,\n  scroll-locked body, Escape and click-outside\n  dismissal). Returns `{ close }` for programmatic\n  dismissal. The `onClose` callback fires on whichever\n  close path triggers first; calling `close()` more\n  than once is a no-op. At most one modal at a time:\n  a second `openModal` call before the first is closed\n  dismisses the first (fires its `onClose`) and\n  replaces it. Safe to call from a `:state` listener;\n  if called before the SPA has mounted, the modal\n  renders as soon as the mount completes.\n\n  ```ts\n  tm.addEventListener('transpareo-time-machine:state', (e) => {\n    // The event re-fires on every step, and another\n    // integration may have slotted a child of its own,\n    // so dedupe on a marker this integration owns\n    // rather than on the slot name.\n    if (tm.querySelector(':scope > [data-newsletter-cta]')) return\n    const button = document.createElement('button')\n    button.textContent = 'Sign up'\n    button.addEventListener('click', () => {\n      const body = document.createElement('div')\n      body.textContent = 'Newsletter form goes here.'\n      const handle = tm.openModal({\n        title: 'Newsletter',\n        body,\n        onClose: () => { /* clean up your form state */ },\n      })\n      // handle.close() to dismiss programmatically.\n    })\n    const wrap = document.createElement('div')\n    wrap.slot = 'additional'\n    wrap.dataset.newsletterCta = ''\n    wrap.appendChild(button)\n    tm.appendChild(wrap)\n  })\n  ```\n\n### `<dpp-verifier>`\n\nStandalone verification widget (no full passport\nchrome). Imported via the subpath entry\n`transpareo-time-machine/dpp-verifier`. Transpareo runs\nit in production at\n[transpareo.com/en/dpp-verifier](https://transpareo.com/en/dpp-verifier).\n\n| Attribute | Required | Effect |\n|-----------|----------|--------|\n| `src` | no | Manifest URL. Pre-fills the input and verifies on connect. |\n| `pinned-platform-key` | no | One or more multibase z-prefixed public keys, whitespace-separated (Ed25519 for `eddsa-jcs-2022` snapshots, P-256 for `ecdsa-sd-2023` ones; a publisher's history can span both, and rotation keeps retired-but-sound keys in the set). An additional security layer for the host's own platform: it never gates pass/fail (foreign DPPs still verify on their own terms), it elevates the identity tier to the strongest claim when the signatures match one of the pins. |\n| `locale` | no | Which language to render the widget in: a tag (`locale=\"de\"`), `inherit` to follow the language surrounding the element, or `auto` (the default, and what an absent attribute means) to detect from the visitor's browser. Outranks `lang`. Only locales with a shipped label bundle apply. |\n| `lang` | no | Standard HTML locale for the widget UI (e.g. `lang=\"de\"`, `lang=\"de-AT\"`; the region is stripped). The verifier has no DPP `availableLocales` to detect from, so without this it stays English. Outranks the browser preference and any locale the visitor picked on another page; a pick they made on a page carrying this same `lang` still wins, so an in-page picker keeps its promise. Only locales with a shipped label bundle apply. |\n\nThe widget verifies any DPP, and the banner says exactly\nwhat was proven, in three identity tiers:\n\n1. **Pinned** - a verified proof entry matched the\n   page-supplied `pinned-platform-key` and the manifest\n   signature verified under it. \"Verified by {platform}\"\n   backed by a key the *page*, not the data, vouched for.\n   This is the layer to deploy on your own verification\n   surface.\n2. **Bound** - no pin (or a foreign DPP): the signing\n   keys resolved from the same domain the manifest's\n   `platform.did` declares (`did:web`). Forging this\n   requires controlling that domain, so the banner still\n   reads \"Verified by {platform}\".\n3. **Unconfirmed** - the signatures verify and the\n   version chain holds, but nothing ties the keys to the\n   declared platform identity. The banner reads\n   \"Signatures valid, signer identity unconfirmed\"\n   instead of carrying a name the data merely claims.\n\nSignature failures, a broken chain, or an invalid\nmanifest signature fail the verdict outright in every\ntier.\n\nSame surface notes as `<transpareo-time-machine>` (open\nshadow root, CSS custom properties, no events). The widget\nstates no width of its own and fills the element's box, so\nthe page sets the measure by sizing the container it drops\nthe element into.\n\n## Proof cryptosuites\n\nA snapshot's embedded proof names its `cryptosuite`, and the\nverifier dispatches on it, so one build verifies either:\n\n- **`eddsa-jcs-2022`** - a whole-document Ed25519 proof set\n  (issuer + platform, multi-authority). JCS-canonicalize the\n  snapshot without its proof, SHA-256, verify each entry.\n  The Nordic Wear demo uses this.\n- **`ecdsa-sd-2023`** - a W3C selective-disclosure proof\n  (P-256, RDF Dataset Canonicalization). Each snapshot is a\n  Verifiable Credential whose proof commits to each statement\n  independently, so a per-reader subset of fields can be\n  disclosed and still verify. The Volturra Pulse 2000 demo\n  uses this.\n\nBoth verifiers are hand-written and vendored under\n`src/crypto/`, with no runtime dependencies. The two cached\nJSON-LD contexts the ecdsa-sd path canonicalizes against\n(`src/contexts/`) ship with the bundle, so verification stays\nfully offline.\n\n**Verify it yourself.** The proof modal (opened from the\nverification chip) prints, for the active version, the\nsnapshot's cryptosuite and the verificationMethod URL of every\nkey that signed it, and each version row has a download button\nfor the raw signed snapshot. To reproduce a check without this\ncode:\n\n- **`eddsa-jcs-2022`** - strip the `proof` array,\n  JCS-canonicalize (RFC 8785) the remaining document and\n  SHA-256 it; then for each proof entry SHA-256 its proof\n  options, concatenate the two hashes, and Ed25519-verify\n  against the key its verificationMethod resolves to.\n  `src/crypto/verify.ts` is the reference.\n- **`ecdsa-sd-2023`** - follow the W3C ecdsa-sd-2023 verify\n  algorithm: parse the CBOR `proofValue`, RDFC-canonicalize the\n  document against the cached contexts, and P-256-verify the\n  base signature over `proofHash || publicKey || mandatoryHash`\n  plus each disclosed statement. `src/crypto/ecdsa-sd.ts` is the\n  reference.\n\n## Browser support\n\nThe renderer runs entirely in the visitor's browser.\n`eddsa-jcs-2022` verification uses **Ed25519**: native\nWebCrypto where the engine supports it, and a bundled pure-JS\nfallback (`noble-ed25519`, lazily imported) everywhere else,\nso the verification chip resolves to a real verdict even on\nengines without native Ed25519. Keys import as `spki`, the\nonly format Firefox accepts for Ed25519. `ecdsa-sd-2023` uses\n**P-256**, which every WebCrypto engine supports natively, so\nit needs no fallback.\n\nNative WebCrypto Ed25519 ships enabled by default in:\n\n| Engine | Native Ed25519 since |\n|--------|---------|\n| Chrome / Edge | 137 (May 2025) |\n| Firefox | 129 (August 2024) |\n| Safari (macOS / iOS) | 17 (September 2023) |\n\nBelow those versions the fallback verifier runs instead\n(slower, same verdict; its chunk downloads only when\nnative support is absent). The practical floor is then\nset by the other web-platform features the bundle relies\non (custom elements, ES-module dynamic `import()`, shadow\nDOM, CSS `color-mix()`), not by Ed25519 support.\n\n## Quick start\n\nFor working on the renderer itself. (Consumers do not\nneed any of this; see \"Using it in a host page\" above.)\n\nPrerequisites:\n\n- Node 22+ (`package.json` `\"type\": \"module\"`)\n- A Rails resolver is only needed in production; in\n  dev the SPA fetches its DPP artefacts from Vite's\n  own `/public/` after `npm run seed`.\n\n```bash\nnpm install\nnpm run seed   # one-off: validates fixture YAML, fetches\n               # external images, and writes the signed\n               # JSON artefacts (manifest, per-version\n               # snapshots, EPCIS document, issuer key\n               # resolution docs) under\n               # /public/<id>/dpp/<code>/.\nnpm run dev\n```\n\nVite serves the SPA on `http://localhost:5173/` and\nhot-reloads on save.\n\n| Command | What it does |\n|---|---|\n| `npm run dev` | Vite dev server with HMR; serves the nordic-wear demo. |\n| `npm run dev:nordic` / `npm run dev:volturra` | Same dev server pointed at a specific seeded fixture. Set `SEED=<fixture-id>` to use any other `fixtures/*.yml`. |\n| `npm run build` | Type-check + bundle into `dist/`. |\n| `npm run preview` | Serve the built `dist/` locally. |\n| `npm run check` | `tsc` over the SPA + the seed scripts + tests. |\n| `npm test` | Vitest. Covers crypto (JCS, multibase, eddsa-jcs-2022 aggregate verifier) and the reactive runtime. |\n| `npm run seed` | Walk every `fixtures/*.yml`, validate against the zod schema, download remote images, write `branding.css` under `/public/<id>/`, and write the published JSON artefacts (manifest, per-version snapshots, EPCIS document, key resolution docs) under `/public/<id>/dpp/<code>/`. Generates a fresh Ed25519 keypair per fixture on each run; the produced snapshots are signed with these keys. A `publication: single-snapshot` fixture with `proof_suite: none` emits just one unsigned `snapshot.json` instead (no manifest, no keys). Idempotent on image cache; output JSON overwrites. Re-run after pulling a fixture change. |\n| `npm run demo` | Re-record the animated loop at the top of this README. Drives the dev page through the nordic-wear passport's history with a Chromium screencast running, then encodes the frames to `docs/demo.webp`. Needs `ffmpeg` on PATH and a seeded `/public/`; reuses a dev server already on :5173 and otherwise starts its own. Pass `--keep-frames` to retune the encode without re-recording. |\n| `npm run check:fixtures` | Network-free Zod parse of every `fixtures/*.yml`. CI runs this on every push and PR to catch schema regressions without depending on third-party image hosts. |\n\n## Fixtures\n\nEach demo product is a single YAML file under\n`fixtures/`, optionally paired with a\n`fixtures/<id>/branding/` folder for non-text assets\n(CSS body, logo, favicon). The seed pipeline turns each\nYAML into the same shape the production issuer writes\nto S3: one manifest, one self-contained per-version\nsnapshot, one EPCIS document (the public events feed,\nwith renderer-specific fields carried as\n`transpareo:*` extensions), and a Multikey resolution\ndoc per signing authority.\n\nThe third fixture deviates on purpose:\n`atelier-barro-vase` declares\n`publication: single-snapshot` and `proof_suite: none`,\nso it emits one frozen, unsigned `snapshot.json` and\nnothing else - no manifest, no EPCIS, no keys, and no\nbranding folder. That is the shape of a foreign DPP\npublished without a version history, and it drives the\nrenderer's question-mark \"Not verifiable\" chip and the\nverifier's nothing-to-judge notice.\n\n```\nfixtures/\n  atelier-barro-vase.yml  # unsigned single snapshot,\n                          # no branding on purpose\n  nordic-wear-tshirt.yml\n  nordic-wear-tshirt/\n    branding/\n      branding.css        # :root issuer theme tokens\n      logo.svg\n      favicon.ico\n  volturra-pulse-2000.yml\n  volturra-pulse-2000/\n    branding/\n      branding.css\n      logo.svg\n      favicon.ico\n```\n\nThe seed run produces, per manifest fixture:\n\n```\npublic/<id>/                              # gitignored\n  branding.css                                # linked from the HTML shell\n  branding/{logo.svg, favicon.ico}            # copied assets\n  icon-map.json                               # row key -> sprite symbol table\n  <fixture-image>.jpg                         # downloaded images\n  dpp/<code>/\n    manifest.json                             # entry point: versions[].url\n                                                + epcisUrl + signature\n    v/<N>.json                                # self-contained snapshots\n                                                with priorVersionHash chain\n                                                + 5-entry proof set\n    epcis.json                                # EPCIS 2.0 events feed\n                                                (with transpareo:* extensions)\n    keys/{issuer,platform}.json               # Ed25519 Multikey docs\n```\n\nA `publication: single-snapshot` fixture reduces to:\n\n```\npublic/<id>/\n  icon-map.json\n  dpp/<code>/\n    snapshot.json                             # one frozen version; with\n                                                proof_suite: none, no proof\n```\n\nNo shipped fixture is out of circulation, so the\nwithdrawal band takes a local edit to see. Add either\nkey to a manifest fixture and re-seed:\n\n```yaml\nvoided:\n  at: 2026-09-13T21:42:31Z\n  reason: recalled          # destroyed | never_shipped | other\nsuperseded_by:\n  code: demo-2026-t002\n  url: https://example.com/01/09524000059116   # optional\n```\n\nThe output tree is gitignored, every dev re-runs the\nseed after pulling a fixture change. The YAML sources\n(under `fixtures/`) and the binary branding assets\n(under `fixtures/<id>/branding/`) are tracked.\n\nThe schema lives in `scripts/seed/schema.ts` (zod),\nthe signer in `scripts/seed/signing.ts`, emission in\n`scripts/seed/emit-artefacts.ts`.\n\n## Seeding\n\n`npm run seed` turns the tracked YAML fixtures into the\nexact artefacts a production issuer would publish, so dev\nruns against real signed data rather than mocks. Per\nfixture it:\n\n1. Validates the YAML against the Zod schema\n   (`scripts/seed/schema.ts`).\n2. Generates a fresh Ed25519 keypair per signing\n   authority (issuer + platform) for that run.\n3. Builds each version's snapshot, computes the\n   `priorVersionHash` chain, signs the multi-entry proof\n   set, and signs the manifest's version list with the\n   platform key (`scripts/seed/signing.ts`).\n4. Downloads and caches the external fixture images.\n5. Writes the manifest, per-version snapshots, EPCIS\n   event feed, branding assets, and Multikey resolution\n   docs under `/public/<id>/dpp/<code>/`\n   (`scripts/seed/emit-artefacts.ts`).\n\nA `publication: single-snapshot` fixture skips the\nmanifest and EPCIS artefacts; with `proof_suite: none`\nit also skips steps 2 and 3 entirely - no keypair, no\nsignatures, one bare `snapshot.json`.\n\nBecause the keypairs are fresh on every run, the\nsignatures (and therefore the verification chip) are only\nvalid against the artefacts from the same seed run. The\noutput tree is gitignored, so re-run `npm run seed` after\npulling a fixture change. `npm run check:fixtures` runs\nonly step 1 (no network) and gates every push.\n\n## Switching fixtures\n\nThe dev pages render whichever fixture `SEED` names.\n`npm run dev` defaults to the nordic-wear demo; the two\nnamed scripts switch the whole page in one shot:\n\n```bash\nnpm run dev:nordic     # SEED=nordic-wear-tshirt\nnpm run dev:volturra   # SEED=volturra-pulse-2000\n```\n\n`SEED=<fixture-id> vite` works for any manifest-publishing\n`fixtures/*.yml`. The id and code are read from that YAML\nand substituted into the `__SEED_ID__` / `__SEED_CODE__`\ntokens in `index.html` and `verifier.html`, so both the\nbranding stylesheet and the manifest `src` follow the\nseed. `snapshot.html` stays on nordic-wear: it pins one\nspecific version (`v/6.json`) that only that fixture has.\n`atelier-barro-vase` is not a `SEED` target (it has no\nmanifest for those tokens to point at); its own page is\n`unsigned.html`.\n\nThere is no build-time fixture selection; every seeded\nDPP is still reachable from any dev session by its own\nURL:\n\n```\n/nordic-wear-tshirt/dpp/demo-2026-t001/manifest.json\n/volturra-pulse-2000/dpp/demo-2026-b001/manifest.json\n/atelier-barro-vase/dpp/demo-2026-c001/snapshot.json\n```\n\nAll are served by Vite from `/public/` after `npm run\nseed` (the third is a lone snapshot, not a manifest).\nProduction hosts use the same shape but point at\nwherever the manifest is published.\n\n## Dev pages\n\nFive HTML entry points live at the repo root for local\nwork; none ship in the npm package:\n\n| Page | Loads | Use |\n|---|---|---|\n| `index.html` | `/src/main.ts` | The full `<transpareo-time-machine>` renderer. The default `npm run dev` page. |\n| `verifier.html` | `/src/dpp-verifier.ts` | The standalone `<dpp-verifier>` widget (no passport chrome). Open `/verifier.html` while `npm run dev` is running. |\n| `embed-example.html` | `dist-embed/embed.js` | Reference host page for the single-file embed build, and the canonical inline list of branding tokens (see \"Theming\"). Run `npm run build:embed` first; see the file's header comment. |\n| `snapshot.html` | `/src/main.ts` | Single-snapshot mode: `src` points at one signed snapshot instead of a manifest, so the renderer shows that frozen version with no timeline/history. Open `/snapshot.html` while `npm run dev` is running. |\n| `unsigned.html` | `/src/main.ts` | The unsigned single snapshot (the `atelier-barro-vase` fixture): no manifest, no proof, no branding. By default it renders with no verification chrome and no brandbar at all; add `show-verification-mark=\"true\"` to the element to see the question-mark \"Not verifiable\" chip and its modal explanation. Open `/unsigned.html` while `npm run dev` is running. |\n\nThe embed delivery is also smoke-tested by\n`tests/embed-smoke.spec.ts` (run under `npm run browser`): it\nloads the built bundle and asserts it registers the custom\nelement and inlines its CSS.\n\nThe browser suite runs on all three engines and a release\ngates on each: `npm run browser` drives Chromium,\n`npm run browser:firefox` drives Gecko, and\n`npm run browser:webkit` drives Safari's. WebKit's Linux\nbuild links against `libicu74` and `libflite`, so on a distro\nshipping neither, `npm run browser:webkit:docker` runs the\nsame suite inside the Playwright container image instead;\n`npm run browser:firefox:docker` does the same for a checkout\nthat would rather not download Firefox.\n`npm run a11y` remains as an alias for `npm run browser`.\n\n## What the SPA does on first paint\n\n1. Browser parses the HTML shell, applies the issuer's\n   `<link rel=\"stylesheet\" href=\"/<id>/branding.css\">`,\n   loads the SPA bundle.\n2. `<transpareo-time-machine>` reads its `src`\n   attribute and hands it to `src/host.ts`, which\n   fetches it and detects a manifest vs a single\n   snapshot. For a manifest it then:\n   1. Resolves `versions[currentVersion].url` and\n      `epcisUrl` against the manifest URL.\n   2. Fetches the current snapshot and the EPCIS\n      document (the single public events feed) in\n      parallel.\n\n   For a single snapshot it stores that one version and\n   leaves the manifest + EPCIS empty (so the timeline and\n   events stay hidden).\n3. `src/host.ts` exposes those fetched docs as signals\n   that `src/state.ts` derives the renderer's view\n   model from (active snapshot, events list, EPCIS\n   lookup). The element only mounts its inner SPA tree\n   once `host.loadState === 'ready'` and the labels for\n   the locale it settled on are in; until then it shows\n   a minimal loading shell. English ships in the main\n   bundle, and the chunk for the likely locale (the\n   host pin, the stored pick, the browser preference)\n   is fetched alongside the manifest, so the first paint\n   is already in the visitor's language rather than\n   opening in English and swapping.\n4. `src/actions.ensureVersionLoaded` runs\n   `verifySnapshot` from `src/crypto/verify.ts` against\n   the current snapshot:\n   - JCS-canonicalize the snapshot (without `proof`),\n     SHA-256 the bytes.\n   - For each of the 5 proof entries: fetch the\n     verificationMethod's Multikey doc, import the\n     Ed25519 public key, `crypto.subtle.verify` the\n     signature against the document hash. Entries that\n     name the same document under different fragments\n     share one read.\n   - Apply the any-issuer-and-any-platform rule\n     (default) or all-five (`{ mode: 'strict' }`) to\n     produce the aggregate verdict.\n   It also walks the priorVersionHash chain back to v1,\n   checking each prior's bytes against the manifest's\n   claim and the next version's claim. Every prior is\n   requested the moment judging starts, so the walk\n   costs one round trip rather than one per link.\n5. The verification chip flips to its verified state\n   once both checks pass for the active\n   version; clicking the chip opens the proof modal\n   with the per-entry chain plus per-version\n   issuer/platform/chain status. Older versions are\n   verified as the visitor scrubs, from the bytes the\n   chain walk already holds.\n\n## Architecture\n\n```\nsrc/\n  main.ts                     lib entry (npm + bundler delivery)\n  embed.ts                    embed entry (script-tag delivery, CSS inlined)\n  bootstrap-spa.ts            global token import + element register\n  bootstrap.ts                first-paint orchestration\n  host.ts                     fetch flow (manifest -> snapshot + EPCIS)\n  state.ts                    signal store + computed derivations\n                              (events derive from EPCIS extensions)\n  actions.ts                  mutations (focus, scrub, snapshot load + verify)\n  archive.ts                  manifest + signature types, VersionState\n  epcis.ts                    EPCIS 2.0 ObjectEvent types\n  pagination.ts               history dot strip math\n  motion.ts                   eased animation primitives\n  gestures.ts                 swipe / drag input\n  icons.ts, config.ts\n  revoked-roots.ts            boot-time pinned-key revocation check\n  types.ts                    localized-scalar tx() + shared types\n  errors.ts                   describeError() for failure messages\n  crypto/\n    jcs.ts                    RFC 8785 canonicalizer\n    multibase.ts              z-base-58 encode/decode\n    verify.ts                 eddsa-jcs-2022 verifier + aggregate verdict\n    dispatch.ts               routes a proof to its cryptosuite verifier\n    ecdsa-sd.ts               ecdsa-sd-2023 derived-proof verifier\n    rdfc.ts                   JSON-LD to N-Quads (RDFC-1.0) for ecdsa-sd\n    base64url.ts, cbor.ts, p256.ts   ecdsa-sd proof-value primitives\n    did-web.ts, buffer.ts     shared verificationMethod + buffer helpers\n  contexts/                   cached JSON-LD contexts (offline ecdsa-sd)\n  i18n/                       label loaders + native locale names\n  reactive/                   tiny signals + html`` template runtime\n                              (no external framework). See\n                              src/reactive/README.md for the\n                              contributor reference.\n  components/                 web components (`<dpp-…>` custom elements,\n    dpp-brandbar.ts             vanilla TS over reactive/)\n    dpp-withdrawal.ts           band for a passport out of circulation\n    dpp-deck.ts\n    dpp-hero.ts\n    dpp-composition-donut.ts\n    dpp-property-cards.ts\n    dpp-badge-lists.ts\n    dpp-accordions.ts\n    dpp-manufacturer.ts\n    dpp-timeline.ts             shim that imports ./timeline/index\n    timeline/                   index.ts (class), layout.ts (math),\n                                ticks.ts (axis), connectors.ts (SVG)\n    dpp-verification-chip.ts\n    dpp-verification-modal.ts\n    dpp-event-modal.ts\n    dpp-footer.ts\n    dpp-gallery.ts\n    dpp-lightbox.ts\n    transpareo-time-machine.ts (the outer custom element + src observer)\n  styles/                     SCSS, `@use`-chained from\n    transpareo-time-machine.scss\n    dpp.scss                  vendored from the Transpareo resolver\n    dpp-*.scss                per-component sheets\n    app.css                   issuer-token derivations + base reset\n```\n\nProduction builds contain zero fixture data. `npm run\nbuild` produces a bundle that fetches its DPP at\nruntime from whatever URL the element's `src` names.\n\nThe runtime is custom: `src/reactive/` provides a tiny\nsignal primitive plus an `html` template tag that\nmounts into a custom element. No Svelte, React, Lit, or\nVue. Components mirror the Transpareo resolver's class\nhierarchy (`<div class=\"dpp-hero\">`, `<h1 class=\"dpp-product-name\">`,\netc.) so the vendored stylesheets apply directly.\n\n`dpp.scss` and `dpp-gallery.scss` are vendored copies of\nthe Transpareo resolver's stylesheets; Transpareo\nmaintainers sync them when the resolver styles change\n(gallery variables are re-resolved to CSS custom\nproperties on the way in, since the SPA bundle carries no\nupstream `_variables.scss`). Treat both as upstream\nfiles: prefer fixing styles in `dpp-*.scss` component\nsheets over patching the vendored pair.\n\n## Theming\n\nPublisher theme tokens are CSS custom properties, shipped\nin the publisher's `branding.css` (the Style Editor\nexport). The SPA's stylesheets read each via\n`var(--token, fallback)`, so a publisher that omits a\ntoken still renders with the SPA defaults.\n\nThe complete, annotated set the renderer reads is set\ninline in the `:root` block of\n[`embed-example.html`](embed-example.html), which doubles\nas the canonical reference; the list lives in one place\nrather than drifting between a doc and the code.\n\nEvery publisher's `branding.css` is the Style Editor\nexport, trimmed only of tokens with no SPA surface\n(`--menu-color-*`, no nav menu; `--keyvisual-url`, no\nbanner image surface). A few exported tokens\n(`--color-highlight*`) are kept for theme completeness\nwithout yet being read by the SPA stylesheets; this is\ndeliberate, the branding export is treated as a complete\ntheme, not trimmed to current usage.\n\nThe typeface follows the same token model: the SPA\nbundles no webfont and makes no external font request.\nA publisher's `branding.css` sets `--font-family` and,\nfor a non-system typeface, ships the matching\n`@font-face`; with no branding (standalone use or the\nverifier surface) the renderer falls back to the system\nsans stack baked into `--font-sans`.\n\nThe `<dpp-verifier>` widget carries that chain in its own\nshadow root, since a page that embeds the widget alone\nloads no SPA stylesheet to declare `--font-sans` for it.\nEvery token it paints with resolves the same way: the\nbranding token first (`--font-family`, `--action-color`,\n`--button-color-*`, `--background-color`), the renderer's\ninternal token second, its own neutral default last.\n\n## Icons\n\nIcons come in two tiers so the renderer's own controls\nnever depend on an externally hosted asset:\n\n- **Functional icons** (controls and status: close,\n  expand, spinner, chevrons, download, history, etc.) ship\n  inline in the bundle as a small sprite injected into the\n  shadow root on boot. They always render, even with no\n  content sprite configured.\n- **Decorative / content icons** (the publisher's icon\n  vocabulary) come from an external sprite the host\n  supplies via `icons-src`, plus a per-publisher map\n  supplied via `icon-map-src` that resolves each\n  property's `propertyID` to a sprite symbol id - the\n  signed snapshot carries no icon, so presentation stays\n  out of the data. The sprite is fetched and injected into\n  the shadow root so a bare `#id` reference resolves\n  same-origin. (A cross-origin `<use href>` is blocked by\n  the browser's same-origin rule, which no CORS header can\n  lift, hence fetch and inject.) In dev they default to\n  the seeded `/icons.svg` and `/<id>/icon-map.json`; a\n  production build has no default. When a content sprite\n  is configured the host gains a `data-icons` attribute,\n  and the stylesheet reserves space for decorative icons\n  only then, so a host or fork without a sprite shows no\n  empty icon boxes.\n\nThe published package ships the functional icons (inline\nin the JS) but no decorative sprite. The full sprite lives\nat `public/icons.svg` for `npm run dev` and is what the\nTranspareo platform publishes to its CDN; consumers point\nthe `icons-src` attribute at their own sprite (or that CDN\ncopy). Several sprite glyphs are converted icon-font\nartwork; see THIRD-PARTY-LICENSES.md for attribution.\n\n### The icon map\n\n`icon-map-src` is a flat JSON object keyed by each\nproperty's `propertyID` (the vocabulary term the snapshot\nships), with sprite symbol names as values:\n\n```json\n{ \"transpareo:carbonFootprint\": \"leaf\",\n  \"transpareo:materialComposition\": \"sliders\" }\n```\n\nA property whose `propertyID` is absent from the map\nrenders with no icon, and the symbol it names must exist\nin the sprite. Like the sprite, the map is a publisher\nresource served by URL, so one map can drive every\npassport. The snapshot itself never carries an icon.\n\n### Referencing an icon\n\nEvery icon is a `<symbol>` addressed by its id. In code,\ncall `icon()` with the bare family name; it adds the\n`icon-` prefix and emits `<use href=\"#id\">`:\n\n```ts\nicon('leaf')         // <use href=\"#icon-leaf\">\nicon('chevron-down') // alias, verbatim: #chevron-down\n```\n\n`chevron-down` and `spinner` are utility aliases that skip\nthe prefix. A property's decorative icon is resolved from\nits `propertyID` through the `icon-map-src` table, and a\nrating maps to a smiley (`smiley-good` ->\n`#icon-smiley-good`); either way the named symbol must\nexist in the configured content sprite. In raw template\nmarkup, reference a symbol with the bare fragment:\n`<use href=\"#icon-leaf\">`.\n\n## Dev wiring\n\n`npm run seed` writes every artefact the renderer fetches\ninto `public/`, so the dev server needs no upstream. To\ndevelop against a live resolver instead, set\n`DPP_ARCHIVE_ORIGIN=https://your-host` and `vite.config.ts`\nproxies these paths to it. With the variable unset there is\nno proxy at all:\n\n| Path | What it serves |\n|---|---|\n| `/dpp/*` | DPP manifest, EPCIS document, version blobs (currently unused at runtime, fixtures cover everything; reserved for a future live-archive mode). |\n| `/.well-known/*` | DPP signing keys. |\n| `/admin/fonts/*` | The shared icon font. |\n| `/app/*` | Plus Jakarta Sans + Lato (`Headline`) variable fonts. |\n| `/media/*` | Publisher mediafile bucket (logo + product images). |\n| `/branding.css` | Issuer branding stylesheet. A production embed serves one publisher per page here; the dev shell links `/<id>/branding.css` so one server can serve several seeded fixtures. |\n\nThe proxy uses `secure: false` only for local-host\ntargets (`*.dev`, `*.local`, `127.0.0.1`, etc.) so the\nresolver's self-signed dev cert doesn't trip Vite;\nreal-cert staging / production hosts get full TLS\nverification. Override with `DPP_ARCHIVE_INSECURE=1`\nif you need to force-skip on a non-local host.\n\n## Localization\n\nTwo layers:\n\n- **DPP content** (product names, event descriptions,\n  etc.), comes from the snapshot's per-locale fields.\n  Scalar localized strings are compact\n  `{ locale: value }` hashes (declared in the\n  snapshot's JSON-LD `@context` with\n  `@container: @language`); single-locale fields stay\n  as plain strings. The renderer's `tx()` helper in\n  `src/types.ts` accepts either shape.\n- **SPA UI labels** (chip text, proof modal headings,\n  event-type labels, etc.), bundled JSON files\n  under `src/i18n/data/`, one per locale, lazy-loaded\n  via Vite. All 40 bundled locales ship.\n\nA property carrying several values (an intended-use list,\na certifications list) tags each value in every locale it\nships, and JSON-LD reads those values as an unordered set:\nnothing in the data pairs one locale's second value with\nanother's. The renderer pairs them by the order the served\ndocument lists them in, per locale, so a publisher emitting\na multi-value property has to keep that order stable across\nlocales. A locale shipping fewer values than the longest\none is left out of the pairing rather than risking a row\nthat reads \"Ski alpin\" in German and \"Snowboarding\" in\nEnglish; `tx()` then falls back to a locale that is there.\nThat order lives in the served document, not in the RDF:\necdsa-sd canonicalization sorts quads, so anything that\nrebuilds a snapshot from N-Quads loses the pairing.\n\nThe locale picker reads `availableLocales` from the\nDPP and shows native names from `src/i18n/index.ts`.\nEach row leads with what the viewer's locale calls the\nlanguage, via `Intl.DisplayNames`, capitalized for the\nlist context: that API answers in the mid-sentence form,\nwhich most locales write lowercase (Italian \"rumeno\"),\nwhere CLDR's list-and-menu rule titlecases the first\nword. Those names are a hint layer, never a dependency:\nan engine without `Intl.DisplayNames`, or one whose data\nanswers in a different language than the viewer's, leaves\nevery row reading as the native name this project ships.\n\nAn element states its language with `locale`: a tag pins\nit, `inherit` follows the language surrounding the element,\nand `auto` (the default) detects. `locale` outranks the\nstandard `lang` attribute, which is still read where no\n`locale` is given.\n\nDetection order: the user's stored pick when they made it\non a page naming the same locale the current one does,\nthen the host page's `lang` attribute when it names an\navailable locale, then that stored pick from any other\ncontext, then `navigator.languages`, then the first\navailable locale. The standalone `<dpp-verifier>`\nhas no DPP locales to draw on, so it resolves `lang`\nagainst the set of shipped label bundles instead.\n\n> Label caveats (`byActor` rendering as colon-style in\n> ja/ko/zh/ru/uk/tr; binary pluralisation in\n> `cryptoProof.snapshotsVerified*` not handling Slavic\n> plural classes) are documented in\n> `src/i18n/data/README.md`.\n\n> **Direction.** All 40 bundled locales are\n> left-to-right. The SPA's stylesheets use physical\n> properties (`left`, `right`, `margin-left`, etc.)\n> and the renderer does not switch\n> `document.documentElement.dir`, so dropping an\n> Arabic, Hebrew, Persian, or Urdu label file in is\n> **not** sufficient to get a correct RTL render.\n> RTL support is tracked separately; until it lands,\n> publishers shipping to RTL markets need a forked\n> bundle.\n\n## Notes\n\n- The Gallery overlay (lightbox) re-parents the\n  `.gallery` element to `document.body` on open,\n  same trick the resolver's `gallery.js` uses to\n  escape ancestor selectors. See\n  `src/components/dpp-lightbox.ts`.\n- The verification chip in `dpp-verification-chip.ts`\n  becomes clickable once verification resolves; clicks\n  open the proof modal.\n- The copy button in the EPCIS raw view\n  (`dpp-event-modal.ts` `.epcis-copy`) is the only\n  surface that consumes `--button-color-*`. Other\n  buttons in the SPA live inside the timeline trough\n  and have their own scrubber-friendly styling.\n- The seeded output under `/public/<id>/dpp/...`\n  and `/public/<id>/branding.css` is gitignored;\n  the YAML sources and `fixtures/<id>/","readmeFilename":"README.md"}