← Home

@archbase/components

6
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

edsonmartins

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@fortune-sheet/core AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:react-modal AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:export-to-csv AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:react-i18next AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:react-chartjs-2 AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:@archbase/layout AI (phantom-deps): Same-org sibling package; used transitively in compiled output. ai
phantom-deps phantom-dep:libphonenumber-js AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:overlayscrollbars AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:react-date-object AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:react-pro-sidebar AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:is-hotkey AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:js-cookie AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:pubsub-js AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:validator AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:classnames AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:jwt-decode AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:pdfjs-dist AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:cep-promise AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:html2canvas AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:js-beautify AI (phantom-deps): Bundled component lib re-exports; dep used transitively in compiled output. ai
phantom-deps phantom-dep:chart.js AI (phantom-deps): Config-referenced dep in a large UI library. ai
phantom-deps phantom-dep:apexcharts AI (phantom-deps): Config-referenced dep in a large UI library. ai
phantom-deps phantom-dep:crypto-js AI (phantom-deps): Config-referenced dep in a large UI library. ai
phantom-deps phantom-dep:react-hook-form AI (phantom-deps): Config-referenced dep in a large UI library. ai
phantom-deps phantom-dep:framer-motion AI (phantom-deps): Config-referenced dep in a large UI library. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): Large component library; deps referenced in config/re-exports, not direct imports. Stable FP. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Same as above — config-referenced dep in a large UI library. ai
provenance no-provenance AI (provenance): Private registry (publishConfig points to local Verdaccio); provenance attestation not applicable. ai
phantom-deps phantom-dep:color AI (phantom-deps): Config-referenced dep in a large UI library. ai

Versions (showing 6 of 6)

Version Deps Published
4.0.20 87 / 15
4.0.4 85 / 15
3.0.5 85 / 13
3.0.4 85 / 13
3.0.2 85 / 13
3.0.0 86 / 12

v4.0.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.