@atproto/oauth-provider-ui
Sign-in & Sign-up UI for the @atproto/oauth-provider
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/messages-T8-auoWR.js | AI (source-diff): i18n message bundle; long lines are JSON string data, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/authorization-page-g790mSI0.js | AI (source-diff): Standard Vite minified React bundle from official atproto monorepo. | ai | |
| source-diff | obfuscated-file:dist/error-view-GA3y_kTW.js | AI (source-diff): Standard Vite minified React bundle from official atproto monorepo. | ai | |
| source-diff | obfuscated-file:dist/index-B5YEVKQn.js | AI (source-diff): Standard Vite minified React bundle from official atproto monorepo. | ai | |
| source-diff | obfuscated-file:dist/messages-4rkLJjBK.js | AI (source-diff): i18n message bundle (Korean locale); long lines are JSON string data, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/messages-BA5oIDGU.js | AI (source-diff): i18n message bundle (Japanese locale); long lines are JSON string data, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/messages-BO47dnxt.js | AI (source-diff): i18n message bundle (Swedish locale); long lines are JSON string data, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/messages-Cy2gaWBQ.js | AI (source-diff): i18n message bundle; long lines are JSON string data, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/account-page-DAZ5oC91.js | AI (source-diff): Standard Vite minified React bundle from official atproto monorepo; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/admonition-DyZGyzv9.js | AI (source-diff): Standard Vite minified React bundle from official atproto monorepo. | ai | |
| source-diff | obfuscated-file:dist/authorization-page-CVdjW3kW.js | AI (source-diff): Vite-minified React UI bundle from official atproto monorepo; source maps included. | ai | |
| source-diff | obfuscated-file:dist/account-page-BWF2SB1c.js | AI (source-diff): Vite-minified React UI bundle from official atproto monorepo; source maps included. | ai | |
| source-diff | obfuscated-file:dist/admonition-yRjCycmU.js | AI (source-diff): Vite-minified React UI bundle from official atproto monorepo; source maps included. | ai | |
| source-diff | obfuscated-file:dist/did-document-YkmTdTdF.js | AI (source-diff): Vite-minified React UI bundle from official atproto monorepo; source maps included. | ai | |
| source-diff | obfuscated-file:dist/error-view-C10M9k8v.js | AI (source-diff): Vite-minified React UI bundle from official atproto monorepo; source maps included. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publisher is consistent with SLSA-attested automated releases from the official atproto monorepo. | ai | |
| source-diff | obfuscated-file:dist/authorization-page-rtYWhk8x.js | AI (source-diff): Standard Vite minified React bundle output; expected for this UI package across all versions. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 0.8.4 | 1 / 33 | |
| 0.7.0 | 0 / 31 | |
| 0.6.0 | 0 / 31 | |
| 0.5.2 | 0 / 31 | |
| 0.4.3 | 0 / 22 | |
| 0.4.1 | 0 / 23 | |
| 0.4.0 | 0 / 23 | |
| 0.3.6 | 0 / 23 | |
| 0.3.5 | 0 / 23 | |
| 0.1.6 | 0 / 22 | |
| 0.1.5 | 0 / 22 | |
| 0.1.4 | 0 / 22 | |
| 0.1.0 | 0 / 22 |
v0.8.4
11 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.