← Home

@amsom-habitat/ui

57
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

amsom-habitat

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index-C4zmv6YW.js AI (source-diff): Vite/esbuild bundled output, minified not obfuscated. ai
source-diff net-exec-file:dist/index.es-D0voDTsf.js AI (source-diff): Bundled polyfill/core-js code misidentified as net-exec; no hostile destination found. ai
source-diff net-exec-file:dist/index.es-7nmkQv5U.js AI (source-diff): core-js polyfill globalThis detection, no fetch/exec of external payload. ai
source-diff obfuscated-file:dist/index-BKSwmFUy.js AI (source-diff): Bundled Vue/fontawesome vendor chunk, minified build output. ai
source-diff obfuscated-file:dist/index-CLFcph8j.js AI (source-diff): Bundled Vue app code, minified build output. ai
source-diff net-exec-file:dist/index.es-IgSaRC2u.js AI (source-diff): Bundled core-js polyfill code, not a dropper; imports local chunk only. ai
source-diff net-exec-file:dist/index.es-D6CrSRsj.js AI (source-diff): Bundled core-js/polyfill code; no concrete malicious network/exec behavior found in sample. ai
phantom-deps phantom-dep:vue AI (phantom-deps): Peer-style dep referenced via build config, common false positive. ai
source-diff obfuscated-file:dist/index-qKfHrY4C.js AI (source-diff): Vite/esbuild bundle output pulling in vue/fontawesome deps, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-COVQdUJm.js AI (source-diff): Vite/esbuild bundle output including vue + fontawesome deps, not obfuscated. ai
source-diff net-exec-file:dist/index.es-pvV8OnXe.js AI (source-diff): Bundled core-js/polyfill code from new deps, no hostile network destination found. ai
phantom-deps phantom-dep:bootstrap AI (phantom-deps): Used via config/CSS, common for UI libraries. ai
source-diff net-exec-file:dist/index.es-Bqx6-ruy.js AI (source-diff): core-js globalThis polyfill pattern, no actual dropper behavior. ai
source-diff obfuscated-file:dist/index-tq87xUMU.js AI (source-diff): Bundled Vue/fontawesome build output, not obfuscated malware. ai
source-diff obfuscated-file:dist/purify.es-BwOkayRK.js AI (source-diff): Bundled DOMPurify with license header, standard dep. ai
source-diff obfuscated-file:dist/index-Bgi55jaM.js AI (source-diff): Vite/rollup bundled Vue app code, minified not obfuscated. ai
source-diff source-size-tripled AI (source-diff): Explained by new deps (fontawesome, html2canvas, dompurify) bundled into dist. ai
source-diff net-exec-file:dist/index.es-WLofdF-d.js AI (source-diff): Bundled core-js/globalThis polyfill code, not a dropper. ai
source-diff obfuscated-file:dist/html2canvas.esm-d2sM-0Wm.js AI (source-diff): Bundled third-party lib (html2canvas) with license header, not obfuscation. ai
source-diff net-exec-file:dist/index.es-BhzEj6YA.js AI (source-diff): Standard polyfill pattern (Function('return this')); no real network+exec threat. ai
source-diff encoded-string-file:dist/ui.umd.cjs AI (source-diff): UMD bundle with license text and TS helpers; not malicious payloads. ai
source-diff obfuscated-file:dist/index-DW6kT0Fx.js AI (source-diff): Vite-bundled Vue component library output; minification is expected. ai
source-diff obfuscated-file:dist/html2canvas-CDGcmOD3.js AI (source-diff): Minified bundle of html2canvas library; standard Vite build output for this UI package. ai
source-diff obfuscated-file:dist/purify-BfsPID7W.js AI (source-diff): Minified bundle of DOMPurify library; standard Vite build output for this UI package. ai
source-diff net-exec-file:dist/index.es-BkqYVoOB.js AI (source-diff): Function('return this')() is core-js global detection; no actual network+exec malware pattern present. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): Scoped org package @amsom-habitat/ui; not a typosquat of uuid. ai
phantom-deps phantom-dep:@fortawesome/free-regular-svg-icons AI (phantom-deps): FontAwesome icons; used in bundled dist. ai
phantom-deps phantom-dep:@fortawesome/free-brands-svg-icons AI (phantom-deps): FontAwesome icons; used in bundled dist. ai
phantom-deps phantom-dep:@fortawesome/free-solid-svg-icons AI (phantom-deps): FontAwesome icons; used in bundled dist. ai
phantom-deps phantom-dep:@fortawesome/fontawesome-svg-core AI (phantom-deps): FontAwesome core; used in bundled dist. ai
phantom-deps phantom-dep:@fortawesome/vue-fontawesome AI (phantom-deps): FontAwesome Vue integration; used in bundled dist. ai
phantom-deps phantom-dep:@amsom-habitat/bootstrap-5 AI (phantom-deps): Same org scope; used in bundled dist components. ai
phantom-deps phantom-dep:@amsom-habitat/amsom-table AI (phantom-deps): Same org scope; used in bundled dist components. ai
phantom-deps phantom-dep:@amsom-habitat/amsom-modal AI (phantom-deps): Same org scope; used in bundled dist components. ai
phantom-deps phantom-dep:@amsom-habitat/file-utils AI (phantom-deps): Same org scope; used in bundled dist components. ai
phantom-deps phantom-dep:@amsom-habitat/date-utils AI (phantom-deps): Same org scope; used in bundled dist components. ai
phantom-deps phantom-dep:vue-draggable-next AI (phantom-deps): Vue UI library; dep used in components bundled into dist. ai
phantom-deps phantom-dep:moment-timezone AI (phantom-deps): Likely used in bundled dist or re-exported; stable false positive for this package. ai
phantom-deps phantom-dep:pdf-merger-js AI (phantom-deps): UI library; deps may be re-exported or used in bundled dist without direct import in analyzed source. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped org package; not a typosquat of yup. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped org package; not a typosquat of joi. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped org package; not a typosquat of qs. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped org package; not a typosquat of pg. ai

Versions (showing 57 of 57)

Version Deps Published
2.20.22 13 / 16
2.20.21 13 / 16
2.20.20 13 / 16
2.20.19 13 / 16
2.20.15 14 / 18
2.20.14 14 / 18
2.20.13 14 / 18
2.20.12 14 / 18
2.20.11 14 / 18
2.20.10 14 / 18
2.20.9 14 / 18
2.20.8 13 / 18
2.20.7 12 / 18
2.20.6 12 / 18
2.20.5 12 / 18
2.20.4 12 / 18
2.20.3 12 / 18
2.19.2 12 / 18
2.19.1 12 / 18
2.19.0 12 / 18
2.18.0 12 / 18
2.16.0 12 / 18
2.15.2 12 / 18
2.15.1 12 / 18
2.15.0 12 / 18
2.14.9 12 / 18
2.14.8 12 / 18
2.14.7 12 / 18
2.14.6 12 / 18
2.14.5 12 / 18
2.14.2 12 / 18
2.14.1 12 / 18
2.14.0 12 / 18
2.9.2 7 / 18
2.9.1 7 / 18
2.8.0 7 / 18
2.7.0 7 / 18
2.6.2 7 / 18
2.5.4 7 / 18
2.5.3 7 / 18
2.5.2 7 / 18
2.5.1 7 / 18
2.5.0 7 / 18
2.4.14 7 / 18
2.4.13 7 / 18
2.4.11 7 / 18
2.4.9 7 / 18
2.4.8 7 / 18
2.4.7 7 / 18
2.4.6 7 / 18
2.4.5 7 / 18
2.4.4 7 / 18
2.4.3 7 / 18
2.4.2 7 / 18
2.4.1 7 / 18
2.4.0 7 / 18
2.3.0 7 / 18

v2.14.9

5 findings
HIGH New obfuscated file: dist/html2canvas.esm-d2sM-0Wm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CLFcph8j.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.es-IgSaRC2u.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/purify.es-BwOkayRK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.14.8

5 findings
HIGH New obfuscated file: dist/html2canvas.esm-d2sM-0Wm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-C4zmv6YW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.es-D0voDTsf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/purify.es-BwOkayRK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.14.7

5 findings
HIGH New obfuscated file: dist/html2canvas.esm-d2sM-0Wm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-qKfHrY4C.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.es-D6CrSRsj.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/purify.es-BwOkayRK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.14.6

5 findings
HIGH New obfuscated file: dist/html2canvas.esm-d2sM-0Wm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-tq87xUMU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.es-Bqx6-ruy.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/purify.es-BwOkayRK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.14.5

5 findings
HIGH New obfuscated file: dist/html2canvas.esm-d2sM-0Wm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-COVQdUJm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.es-pvV8OnXe.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/purify.es-BwOkayRK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.14.2

5 findings
HIGH New obfuscated file: dist/html2canvas.esm-d2sM-0Wm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BKSwmFUy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.es-7nmkQv5U.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/purify.es-BwOkayRK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.14.1

5 findings
HIGH New obfuscated file: dist/html2canvas.esm-d2sM-0Wm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Bgi55jaM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.es-WLofdF-d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/purify.es-BwOkayRK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.14.0

5 findings
HIGH New obfuscated file: dist/html2canvas.esm-d2sM-0Wm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Bgi55jaM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.es-WLofdF-d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/purify.es-BwOkayRK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.