@aurodesignsystem/auro-tail
auro-tail HTML custom element
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/auro-tail-group-ABQD2bqA.js | AI (source-diff): Bundled minified lit component code, not obfuscation; no malicious behavior. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Trusted-publisher provenance confirms legitimate CI/CD transfer, not compromise. | ai | |
| phantom-deps | phantom-dep:lit | AI (phantom-deps): lit is used via build tooling/config, standard for this framework. | ai |
v2.0.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (jordanjones243) than the most recent previously approved version (rmenner-aa) on 2026-05-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.