← Home

@bcc-code/vue-bcc-chat-ui

45
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

karsten.kueppernbogdanit.accountsadelinnlaurensgroeneveldu12206050jakubc-projects

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@cometchat/chat-sdk-javascript AI (dependencies): CometChat is the documented chat backend for this package; expected dependency. ai
dependencies unvetted-dep:markdown-it AI (dependencies): Well-known markdown parser; stable dependency for a chat UI package. ai
phantom-deps phantom-dep:panzoom AI (phantom-deps): panzoom is a declared runtime dep used in bundled output; phantom detection is a false positive for this bundled library. ai
phantom-deps phantom-dep:@cometchat/uikit-elements AI (phantom-deps): CometChat UIKit elements are bundled; not directly imported at source level but legitimately used. ai
npm-metadata no-description AI (npm-metadata): Established scoped package; missing description is a cosmetic issue, not a risk signal. ai
provenance no-provenance AI (provenance): Published via GitHub Actions CI; no provenance attestation but no other risk signals present. ai
source-diff obfuscated-file:dist/vue-bcc-chat-ui.js AI (source-diff): Standard Vite-bundled minified output for a Vue component library; not obfuscated malware. ai
bogus-package bogus-package AI (bogus-package): Established org package with 181 versions; missing metadata is a CI publishing artifact, not spam. ai
phantom-deps phantom-dep:@cometchat/chat-sdk-javascript AI (phantom-deps): Chat SDK referenced in config for bundling; stable FP. ai
phantom-deps phantom-dep:@bcc-code/component-library-vue AI (phantom-deps): Same-org component library; stable FP. ai
phantom-deps phantom-dep:@capacitor/browser AI (phantom-deps): Capacitor browser plugin referenced in config; stable FP. ai
phantom-deps phantom-dep:vue AI (phantom-deps): Vue is a peer dep declared in config; phantom-dep heuristic false positive for this component library. ai
phantom-deps phantom-dep:primevue AI (phantom-deps): UI library dependency referenced in build config; stable false positive for this package. ai
phantom-deps phantom-dep:primeicons AI (phantom-deps): Icon set referenced in build/style config; stable false positive. ai
phantom-deps phantom-dep:@capacitor/app AI (phantom-deps): Capacitor deps used for mobile integration; referenced in config files, stable FP. ai
phantom-deps phantom-dep:@capacitor/core AI (phantom-deps): Capacitor core referenced in config; stable FP for this package. ai
phantom-deps phantom-dep:@primeuix/themes AI (phantom-deps): PrimeVue theming package referenced in config; stable FP. ai
phantom-deps phantom-dep:@bcc-code/design-tokens AI (phantom-deps): Same-org design tokens package; stable FP for this component library. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): UI library; deps may be used in bundled output without direct import visible to static analysis. ai
phantom-deps phantom-dep:@bcc-code/icons-vue AI (phantom-deps): Same org scope; bundled into dist output, stable false positive. ai
phantom-deps phantom-dep:@auth0/auth0-spa-js AI (phantom-deps): Same as auth0-vue — bundled library pattern. ai
phantom-deps phantom-dep:@auth0/auth0-vue AI (phantom-deps): Auth0 SDK used as a runtime dep in a Vue component library; bundled output may not show direct import. ai
phantom-deps phantom-dep:markdown-it AI (phantom-deps): Same as dompurify — bundled library pattern, not a real phantom dep. ai

Versions (showing 45 of 45)

Version Deps Published
7.1.21 6 / 23
7.1.20 6 / 23
7.1.19 6 / 23
7.1.18 6 / 23
7.1.17 6 / 23
7.1.16 6 / 23
7.1.15 6 / 23
7.1.14 6 / 23
7.1.13 6 / 23
7.1.12 6 / 23
7.1.11 6 / 23
7.0.43 7 / 23
7.0.42 7 / 23
7.0.41 7 / 23
7.0.40 7 / 23
7.0.38 7 / 23
7.0.36 7 / 23
7.0.35 7 / 23
7.0.34 7 / 22
7.0.32 7 / 22
7.0.31 7 / 22
7.0.30 7 / 22
7.0.29 7 / 22
7.0.28 7 / 22
7.0.26 7 / 22
7.0.25 7 / 22
7.0.23 7 / 22
7.0.17 7 / 22
7.0.16 7 / 11
7.0.15 7 / 11
7.0.14 7 / 11
7.0.13 7 / 11
7.0.12 7 / 11
7.0.11 7 / 11
7.0.10 7 / 11
7.0.9 7 / 11
7.0.8 7 / 11
7.0.7 7 / 11
7.0.6 7 / 11
7.0.5 7 / 11
7.0.4 7 / 11
7.0.3 7 / 11
7.0.2 14 / 11
7.0.1 14 / 11
6.5.0 9 / 17

v7.1.21

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.43

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.42

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.41

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.40

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.38

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.36

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.35

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.34

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.32

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.31

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.30

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.29

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.28

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.26

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.25

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.23

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.0.6

2 findings
HIGH New obfuscated file: dist/vue-bcc-chat-ui.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.5

2 findings
HIGH New obfuscated file: dist/vue-bcc-chat-ui.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.4

2 findings
HIGH New obfuscated file: dist/vue-bcc-chat-ui.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.3

2 findings
HIGH New obfuscated file: dist/vue-bcc-chat-ui.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.