@bgord/ui
Clone the repository
48
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
bgord
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Small personal UI library; no provenance is consistent across all 72 versions; not a meaningful risk signal here. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): polish-plurals is a well-scoped pluralization utility; no malicious indicators. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Personal scoped UI library (@bgord/ui); no repo/keywords expected for internal tooling with 70 published versions. | ai | |
| dependencies | unvetted-dep:polish-plurals | AI (dependencies): Small i18n utility; no known malicious history, consistent with a UI library targeting Polish locale. | ai | |
| dependencies | unvetted-dep:tinykeys | AI (dependencies): tinykeys is a well-known keyboard shortcut library; stable false positive for this UI package. | ai | |
| phantom-deps | phantom-dep:js-cookie | AI (phantom-deps): UI library likely re-exports or conditionally uses js-cookie; phantom-dep heuristic is unreliable for this package. | ai | |
| phantom-deps | phantom-dep:tinykeys | AI (phantom-deps): UI library likely re-exports or conditionally uses tinykeys; phantom-dep heuristic is unreliable for this package. | ai | |
| phantom-deps | phantom-dep:polish-plurals | AI (phantom-deps): UI library likely re-exports or conditionally uses polish-plurals; phantom-dep heuristic is unreliable for this package. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped package @bgord/ui is not a typosquat of uuid; Levenshtein false positive. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped package @bgord/ui is not a typosquat of yup; Levenshtein false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @bgord/ui is not a typosquat of joi; Levenshtein false positive. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped package @bgord/ui is not a typosquat of qs; Levenshtein false positive. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package @bgord/ui is not a typosquat of pg; Levenshtein false positive. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): bunx only-allow bun is a standard package-manager enforcement tool; stable pattern for this package. | ai |
Versions (showing 48 of 48)
| Version | Deps | Published |
|---|---|---|
| 0.10.1 | 2 / 18 | |
| 0.10.0 | 2 / 18 | |
| 0.9.4 | 2 / 18 | |
| 0.9.3 | 2 / 18 | |
| 0.9.2 | 2 / 19 | |
| 0.8.37 | 3 / 22 | |
| 0.8.34 | 3 / 22 | |
| 0.8.33 | 3 / 22 | |
| 0.8.30 | 3 / 21 | |
| 0.8.29 | 3 / 20 | |
| 0.8.25 | 3 / 20 | |
| 0.8.24 | 3 / 20 | |
| 0.8.23 | 3 / 20 | |
| 0.8.22 | 3 / 20 | |
| 0.8.21 | 3 / 20 | |
| 0.8.20 | 3 / 20 | |
| 0.8.19 | 3 / 20 | |
| 0.8.18 | 3 / 20 | |
| 0.8.17 | 3 / 20 | |
| 0.8.16 | 3 / 19 | |
| 0.8.14 | 3 / 18 | |
| 0.8.13 | 3 / 18 | |
| 0.8.12 | 3 / 18 | |
| 0.8.11 | 3 / 18 | |
| 0.8.10 | 3 / 18 | |
| 0.8.9 | 3 / 17 | |
| 0.8.8 | 3 / 17 | |
| 0.8.3 | 3 / 17 | |
| 0.8.1 | 3 / 17 | |
| 0.8.0 | 3 / 17 | |
| 0.7.9 | 3 / 17 | |
| 0.7.8 | 3 / 17 | |
| 0.6.1 | 4 / 17 | |
| 0.5.13 | 4 / 17 | |
| 0.5.12 | 4 / 17 | |
| 0.5.11 | 4 / 17 | |
| 0.5.10 | 4 / 17 | |
| 0.5.9 | 4 / 17 | |
| 0.5.8 | 4 / 17 | |
| 0.5.7 | 4 / 17 | |
| 0.5.4 | 4 / 17 | |
| 0.4.1 | 1 / 16 | |
| 0.4.0 | 1 / 16 | |
| 0.3.0 | 0 / 16 | |
| 0.2.0 | 0 / 16 | |
| 0.1.2 | 0 / 2 | |
| 0.1.1 | 0 / 2 | |
| 0.1.0 | 0 / 2 |
v0.10.1
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.4
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.