← Home

@c15t/react

12
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

kayleewburnedchris

Keywords

reactreact-consentreact-cookie-bannerreact-cookie-consentconsentprivacygdprccpalgpdtcfiabcmpheadlesstypescriptcookie-bannercookie-consentconsent-management-platformconsent-managementconsent-bannerconsent-manager-reactpreference-centerreact-server-componentsrscuse-clienttracking-consent

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; legitimate automation handoff for this package. ai
source-diff obfuscated-file:dist/providers/__tests__/provider-hydration.test.cjs AI (source-diff): Minified test bundle produced by rslib build tool; not a runtime file, no malicious content. ai
phantom-deps phantom-dep:zustand AI (phantom-deps): zustand is listed as a direct dependency in package.json; phantom-dep heuristic is a false positive here. ai
provenance slsa-provenance AI (provenance): Package is published via CI/CD with Sigstore SLSA attestation; stable supply chain signal for this package. ai

Versions (showing 12 of 12)

Version Deps Published
2.1.0 2 / 7
2.0.4 2 / 7
2.0.3 2 / 7
2.0.2 2 / 7
2.0.0 2 / 7
1.8.6 6 / 4
1.8.5 6 / 4
1.8.4 6 / 4
1.8.3 6 / 4
1.8.2 6 / 4
1.8.1 6 / 4
1.8.0 6 / 4

v2.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.6

3 findings
HIGH Publisher changed: burnedchris → GitHub Actions (on 2026-04-05) provenance

This version was published by a different npm account than previous versions on 2026-04-05. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/providers/__tests__/provider-hydration.test.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.5

3 findings
HIGH Publisher changed: burnedchris → GitHub Actions (on 2026-03-12) provenance

This version was published by a different npm account than previous versions on 2026-03-12. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/providers/__tests__/provider-hydration.test.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.4

3 findings
HIGH Publisher changed: burnedchris → GitHub Actions (on 2026-03-12) provenance

This version was published by a different npm account than previous versions on 2026-03-12. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/providers/__tests__/provider-hydration.test.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.3

3 findings
HIGH Publisher changed: burnedchris → GitHub Actions (on 2026-01-19) provenance

This version was published by a different npm account than previous versions on 2026-01-19. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/providers/__tests__/provider-hydration.test.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.2

3 findings
HIGH Publisher changed: burnedchris → GitHub Actions (on 2025-12-12) provenance

This version was published by a different npm account than previous versions on 2025-12-12. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/providers/__tests__/provider-hydration.test.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.