@atria/admin
Modular admin runtime UI for atria
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/frontend/a81/329/4c0e9bfe.js | AI (source-diff): Standard minified React component bundle; no malicious patterns in sample. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/92af58dc.js | AI (source-diff): Minified app state/routing bundle; no exfiltration or malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/8ec1ac2b.js | AI (source-diff): Minified React runtime bundle; content is clearly the React library itself. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/6031887a.js | AI (source-diff): Standard minified React bundle; content shows auth UI components only. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/ed684070.js | AI (source-diff): Minified React bundle produced by Rollup+terser; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/1fa8a901.js | AI (source-diff): Minified React bundle produced by Rollup+terser; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/c85f5f3f.js | AI (source-diff): Minified React bundle produced by Rollup+terser; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/ddb5906d.js | AI (source-diff): Minified React bundle produced by Rollup+terser; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/74b27db6.js | AI (source-diff): Standard Rollup minified frontend bundle; readable React/auth logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/a7ddcee0.js | AI (source-diff): Minified React sidebar/nav bundle; readable logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/runtime/auth/screen/states/create/CreateForm.js | AI (source-diff): Minified React form component; no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/ed325ba9.js | AI (source-diff): Minified React state/routing bundle; no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/e0a89956.js | AI (source-diff): Minified React auth routing bundle; no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/84dc5f8a.js | AI (source-diff): Standard Rollup/terser minified frontend bundle; content is benign React admin sidebar code. | ai | |
| source-diff | obfuscated-file:dist/frontend/a81/329/7e2682fe.js | AI (source-diff): Standard Rollup/terser minified frontend bundle; content is benign UI/theme code. | ai | |
| source-diff | obfuscated-file:dist/app.js | AI (source-diff): dist/app.js is a Rollup+Terser-minified React bundle; minification is expected for this package's build pipeline. | ai | |
| phantom-deps | phantom-dep:lucide-react | AI (phantom-deps): lucide-react is a declared runtime dep bundled via Rollup; phantom-dep heuristic is a false positive here. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are rollup-bundled React admin UI output; consistent with the stated purpose and build tooling. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase is explained by bundling React app into dist/app.js; not injected payload. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 1.0.0 | 3 / 6 | |
| 0.1.27 | 3 / 6 | |
| 0.1.26 | 3 / 6 | |
| 0.1.24 | 3 / 6 | |
| 0.1.23 | 3 / 6 | |
| 0.1.22 | 2 / 6 | |
| 0.1.21 | 2 / 6 | |
| 0.1.20 | 3 / 8 | |
| 0.1.19 | 3 / 7 | |
| 0.1.18 | 3 / 7 | |
| 0.1.17 | 3 / 7 | |
| 0.1.16 | 3 / 7 | |
| 0.1.14 | 2 / 7 | |
| 0.1.13 | 2 / 7 | |
| 0.1.12 | 2 / 7 | |
| 0.1.11 | 2 / 7 | |
| 0.1.10 | 2 / 7 | |
| 0.1.9 | 2 / 7 | |
| 0.1.8 | 2 / 8 | |
| 0.1.7 | 2 / 8 | |
| 0.1.6 | 2 / 8 | |
| 0.1.5 | 2 / 8 | |
| 0.1.4 | 2 / 8 | |
| 0.1.3 | 2 / 8 | |
| 0.1.2 | 2 / 8 | |
| 0.1.1 | 2 / 8 | |
| 0.0.5 | 0 / 0 | |
| 0.0.4 | 1 / 0 | |
| 0.0.3 | 1 / 0 |
v1.0.0
7 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrialabs.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.27
7 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrialabs.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.26
8 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrialabs.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.20
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.