@blocklet/pages-kit-inner-components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:lib/es/chunks/index-Dm9c1YeI.js | AI (source-diff): ESM bundled chunk with clean imports; build output. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/index-aDzdRTp1.js | AI (source-diff): esbuild-bundled chunk, no malicious behavior. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/home-DeAzY6p9.js | AI (source-diff): esbuild-bundled chunk, no malicious behavior. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/publish-button-BuApNQWc.js | AI (source-diff): esbuild-bundled chunk, no malicious behavior. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/publish-button-DjVJAqts.js | AI (source-diff): Bundled component chunk, no malicious payload. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/index-DDXPTdvW.js | AI (source-diff): Bundled build output consistent with package's declared deps. | ai | |
| source-diff | obfuscated-file:lib/es/chunks/index-B6GyWmgC.js | AI (source-diff): ESM bundle chunk from build pipeline, not obfuscated. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/home-C6w76oIG.js | AI (source-diff): Bundled build output, legitimate imports, no malicious behavior. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/site-state-8lUnv-C3.js | AI (source-diff): Bundled state-management chunk using sequelize/yjs, legitimate. | ai | |
| dependencies | unvetted-dep:@arcblock/did-connect | AI (dependencies): Same publisher's own ecosystem package. | ai | |
| phantom-deps | phantom-dep:defu | AI (phantom-deps): Shared monorepo config dep, not a security concern. | ai | |
| dependencies | unvetted-dep:@arcblock/did-auth-storage-nedb | AI (dependencies): Same publisher's own ecosystem package. | ai | |
| dependencies | unvetted-dep:@mui/base | AI (dependencies): Well-known MUI ecosystem package. | ai | |
| dependencies | unvetted-dep:sequelize | AI (dependencies): Popular established ORM. | ai | |
| dependencies | unvetted-dep:@blocklet/ai-kit | AI (dependencies): Same-org Blocklet package. | ai | |
| dependencies | unvetted-dep:@arcblock/did-auth | AI (dependencies): Same publisher's own ecosystem package. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/publish-button-B5I1Nbu0.js | AI (source-diff): esbuild bundle chunk of app UI code | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/components-D1oFQM3W.js | AI (source-diff): esbuild bundle chunk, legit requires, no malicious payload | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/state-B5PBvcI6.js | AI (source-diff): esbuild bundle chunk of app state code | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/site-state-CIj4DvXS.js | AI (source-diff): esbuild bundle chunk, legit requires (sequelize/yjs/etc) | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/home-DPSHupAh.js | AI (source-diff): esbuild bundle chunk of app UI code | ai | |
| source-diff | obfuscated-file:lib/es/chunks/index-CqrEKyBA.js | AI (source-diff): ESM bundle chunk, readable imports | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/index-BUVSkE9x.js | AI (source-diff): esbuild bundle chunk of app UI code | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/state-tEydRMV8.js | AI (source-diff): Bundled build output, not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/components-CacZMc0_.js | AI (source-diff): esbuild-bundled chunk requiring legit deps; no true obfuscation signature. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/home-CmcR9R89.js | AI (source-diff): Bundled build output, not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/index-7_tPWvdE.js | AI (source-diff): Bundled build output, not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/publish-button-CuIP1HAR.js | AI (source-diff): Bundled build output, not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/site-state-CkqENAbR.js | AI (source-diff): Bundled build output, not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/home-FbBl1G79.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a React UI library; not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/publish-button-JUoM34Aa.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a React UI library; not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/es/chunks/index-BZ1MijZ6.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a React UI library; not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/index-B-TdKJtn.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a React UI library; not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/es/chunks/index-EWs_19jE.js | AI (source-diff): Standard Vite minified bundle output; readable React/MUI code in samples, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/index-ByDnzW6o.js | AI (source-diff): Standard Vite minified bundle output; readable React/MUI code in samples, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/home-BQZXyZ-m.js | AI (source-diff): Standard Vite minified bundle output; readable React/MUI code in samples, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/state-BBnuCgyl.js | AI (source-diff): Standard Vite minified bundle output; readable React/MUI code in samples, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/site-state-oC_X_C59.js | AI (source-diff): Standard Vite minified bundle output; readable React/MUI code in samples, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/cjs/chunks/publish-button-Dv9qNYUI.js | AI (source-diff): Standard Vite minified bundle output; readable React/MUI code in samples, not obfuscation. | ai | |
| phantom-deps | phantom-dep:jss | AI (phantom-deps): Same pattern — bundled component library with transitive deps. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Peer dep; phantom-dep false positive for this package. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Same pattern — bundled component library with transitive deps. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Same pattern — bundled component library with transitive deps. | ai | |
| phantom-deps | phantom-dep:cors | AI (phantom-deps): Same pattern — bundled component library with transitive deps. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): Large monorepo component; phantom deps reflect bundled/transitive usage, not missing imports. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 0.7.38 | 134 / 39 | |
| 0.7.37 | 134 / 39 | |
| 0.7.36 | 134 / 39 | |
| 0.7.35 | 134 / 39 | |
| 0.7.30 | 134 / 39 | |
| 0.7.29 | 134 / 39 | |
| 0.7.28 | 134 / 39 | |
| 0.7.27 | 134 / 39 | |
| 0.7.26 | 134 / 39 | |
| 0.7.25 | 134 / 39 | |
| 0.7.24 | 134 / 39 | |
| 0.7.23 | 134 / 39 | |
| 0.7.22 | 134 / 39 | |
| 0.7.21 | 134 / 39 | |
| 0.7.20 | 134 / 39 | |
| 0.7.19 | 134 / 39 | |
| 0.7.18 | 134 / 39 | |
| 0.7.17 | 134 / 39 | |
| 0.7.16 | 134 / 39 | |
| 0.6.40 | 136 / 40 | |
| 0.6.39 | 136 / 40 | |
| 0.6.35 | 136 / 40 | |
| 0.6.22 | 136 / 40 | |
| 0.5.30 | 137 / 40 | |
| 0.5.9 | 138 / 40 | |
| 0.5.7 | 138 / 40 | |
| 0.4.100 | 138 / 40 |
v0.6.40
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.39
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.35
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.22
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.100
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.