@alfalab/icons
Design System UI Icons
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:flag/dist/AbkhaziaMColorIcon.js | AI (source-diff): Minified bundled icon component, not true obfuscation; expected for icon library dist files. | ai | |
| source-diff | obfuscated-file:logotype/dist/TinkoffBankMColorIcon.js | AI (source-diff): Minified bundled SVG icon component, not true obfuscation. | ai | |
| source-diff | obfuscated-file:logotype/dist/SberBankMColorIcon.js | AI (source-diff): Minified bundled SVG icon component, not true obfuscation. | ai | |
| source-diff | obfuscated-file:logo/dist/EtprfSignBoxMColorIcon.js | AI (source-diff): Minified generated icon component, not obfuscation; matches package's icon-generation purpose. | ai | |
| source-diff | obfuscated-file:logo/dist/GazprombankSignCircleBoxMWhiteIcon.js | AI (source-diff): Minified generated icon component, not obfuscation; matches package's icon-generation purpose. | ai | |
| source-diff | obfuscated-file:logotype/dist/GosuslugiMColorIcon.js | AI (source-diff): Minified icon-component build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:logotype/dist/GosuslugiXlColorIcon.js | AI (source-diff): Minified icon-component build output, not true obfuscation; matches package's stated function. | ai | |
| source-diff | obfuscated-file:ios/dist/TouchIdXxlIcon.js | AI (source-diff): Minified icon-component build output, not true obfuscation. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Stale change from 2022, unremoved for years; not indicative of takeover. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Org migration to core-ds-bot, stable and long-lived publisher account. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same org migration, old maintainers rotated out long ago. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Icon set expansions routinely cause dramatic size increases in this package; consistent with new logo icons added. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Icon library regularly adds large batches of new icon files; size growth matches new icon additions. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped @alfalab/icons package is a legitimate design-system icon library, not a typo of cors. | ai |
Versions (showing 51 of 141)
| Version | Deps | Published |
|---|---|---|
| 3.479.0 | 0 / 37 | |
| 3.478.0 | 0 / 37 | |
| 3.477.0 | 0 / 37 | |
| 3.476.0 | 0 / 37 | |
| 3.475.0 | 0 / 37 | |
| 3.474.0 | 0 / 37 | |
| 3.473.0 | 0 / 37 | |
| 3.472.0 | 0 / 37 | |
| 3.471.0 | 0 / 37 | |
| 3.465.0 | 0 / 37 | |
| 3.464.0 | 0 / 37 | |
| 3.463.0 | 0 / 37 | |
| 3.462.0 | 0 / 37 | |
| 3.461.0 | 0 / 37 | |
| 3.460.0 | 0 / 37 | |
| 3.459.0 | 0 / 37 | |
| 3.458.0 | 0 / 37 | |
| 3.457.0 | 0 / 37 | |
| 3.456.0 | 0 / 37 | |
| 3.455.0 | 0 / 37 | |
| 3.454.0 | 0 / 37 | |
| 3.453.0 | 0 / 37 | |
| 3.452.0 | 0 / 37 | |
| 3.451.0 | 0 / 37 | |
| 3.449.0 | 0 / 37 | |
| 3.433.6 | 0 / 37 | |
| 3.433.3 | 0 / 37 | |
| 3.433.2 | 0 / 37 | |
| 3.430.0 | 0 / 37 | |
| 3.429.0 | 0 / 37 | |
| 3.428.0 | 0 / 37 | |
| 3.427.0 | 0 / 37 | |
| 3.426.0 | 0 / 37 | |
| 3.425.0 | 0 / 37 | |
| 3.424.0 | 0 / 37 | |
| 3.423.1 | 0 / 37 | |
| 3.423.0 | 0 / 37 | |
| 3.422.0 | 0 / 37 | |
| 3.421.0 | 0 / 37 | |
| 3.420.0 | 0 / 37 | |
| 3.419.0 | 0 / 37 | |
| 3.418.0 | 0 / 37 | |
| 3.417.0 | 0 / 37 | |
| 3.416.0 | 0 / 37 | |
| 3.415.2 | 0 / 37 | |
| 3.415.1 | 0 / 37 | |
| 3.414.0 | 0 / 37 | |
| 3.412.0 | 0 / 37 | |
| 3.411.0 | 0 / 37 | |
| 3.410.0 | 0 / 37 | |
| 3.256.0 | 0 / 37 |
v3.479.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.478.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.477.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.476.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.475.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.474.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.473.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.472.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.471.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.449.0
3 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: core-ds-bot.
This version was published by a different npm account (core-ds-bot) than the most recent previously approved version (GitHub Actions) on 2026-03-24, but core-ds-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.433.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.433.3
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (core-ds-bot) on 2026-01-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v3.433.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (core-ds-bot) on 2026-01-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v3.430.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.429.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.428.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.427.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.426.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.425.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.424.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.423.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hextion) than the most recent previously approved version (core-ds-bot) on 2026-01-12, but hextion is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.423.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.422.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.421.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.420.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.419.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.418.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.417.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.416.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.415.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.415.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.411.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.410.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.256.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.