← Home

@bolttech/atoms-date-input

A split date input component with optional calendar (datepicker). It renders three numeric fields (`DD`, `MM`, `YYYY`) and **emits a single controlled value** in the `YYYY-MM-DD` format.

16
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

andsfranboltdanielkhalebbatistapauloazevedo-edbruno.gomesplinio.altoejoaoteixeira20esteve-cabrerajabolttechlucasvpaivaherberts.fortunamatheus.maciel.bolttechsilas.silva.bolttech

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:shady-links-exfil-services AI (semgrep): URL is inside a comment, not executed; long-standing polyfill code. ai
phantom-deps phantom-dep:@bolttech/atoms-input AI (phantom-deps): Same-org scoped sibling package, benign. ai
source-diff net-exec-file:index.cjs.js AI (source-diff): Bundled CJS build output (core-js/react shims), not a dropper; no real net+exec behavior. ai
bogus-package bogus-package AI (bogus-package): Internal design-system component; minimal README/repo metadata is typical, not spam. ai
provenance no-provenance AI (provenance): Internal corporate component library; provenance absence is common and not a risk signal here. ai

Versions (showing 16 of 16)

Version Deps Published
0.4.16 7 / 0
0.4.15 7 / 0
0.4.3 7 / 0
0.4.0 7 / 0
0.3.2 0 / 0
0.3.1 0 / 0
0.3.0 0 / 0
0.2.3 3 / 0
0.2.2 0 / 0
0.2.1 0 / 0
0.2.0 0 / 0
0.1.4 3 / 0
0.1.3 3 / 0
0.1.2 3 / 0
0.1.1 2 / 0
0.1.0 2 / 0

v0.4.16

2 findings
HIGH shady-links-exfil-services: index.cjs.js:2530 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) 2528 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 2529 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 2530 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 2531 | for (var j = 1; j < result.length; j++) push$1(captures, maybeToString(result[j])); 2532 | var namedCaptures = result.groups;

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.15

2 findings
HIGH shady-links-exfil-services: index.cjs.js:2530 semgrep

URL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) 2528 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 2529 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 2530 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 2531 | for (var j = 1; j < result.length; j++) push$1(captures, maybeToString(result[j])); 2532 | var namedCaptures = result.groups;

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

2 findings
HIGH New file with network + code execution: index.cjs.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

2 findings
HIGH New file with network + code execution: index.cjs.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

2 findings
HIGH New file with network + code execution: index.cjs.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

2 findings
HIGH New file with network + code execution: index.cjs.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.