@clef-sh/ui
Local web UI for Clef — git-native secrets management
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/client/assets/index-Db6WgHgY.js | AI (source-diff): Vite-bundled React client asset; minified output is expected for this UI package. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-YcTmzmJ5.js | AI (source-diff): Standard Vite/React minified bundle output; not malicious obfuscation. Expected artifact for this UI package. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DA0UG2qb.js | AI (source-diff): Standard Vite-minified React bundle; long lines are normal minification output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BpvAgeMe.js | AI (source-diff): Standard Vite-minified React bundle; long lines are expected minification output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BVC8eF9m.js | AI (source-diff): Standard Vite/React minified bundle output; not malicious obfuscation. Stable pattern for this UI package. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DPWHjBbB.js | AI (source-diff): Standard Vite/React minified client bundle; not obfuscation. Stable pattern for this UI package. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BvjtHXyF.js | AI (source-diff): Vite-minified React client bundle; long lines are standard minification output, not obfuscation. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped package @clef-sh/ui; Levenshtein match to uuid is a false positive for this namespace. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped package @clef-sh/ui; Levenshtein match to yup is a false positive for this namespace. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @clef-sh/ui; Levenshtein match to joi is a false positive for this namespace. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped package @clef-sh/ui; Levenshtein match to qs is a false positive for this namespace. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package @clef-sh/ui; Levenshtein match to pg is a false positive for this namespace. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 0.1.28 | 7 / 20 | |
| 0.1.27 | 7 / 20 | |
| 0.1.26 | 7 / 20 | |
| 0.1.25 | 7 / 20 | |
| 0.1.24 | 7 / 20 | |
| 0.1.23 | 7 / 20 | |
| 0.1.22 | 7 / 20 | |
| 0.1.21 | 7 / 20 | |
| 0.1.20 | 4 / 18 | |
| 0.1.19 | 4 / 18 | |
| 0.1.18 | 4 / 18 | |
| 0.1.17 | 4 / 18 | |
| 0.1.16 | 4 / 18 | |
| 0.1.15 | 4 / 18 | |
| 0.1.14 | 4 / 18 | |
| 0.1.13 | 4 / 18 |
v0.1.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.26
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.25
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.24
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.23
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.22
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.21
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.20
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.19
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.18
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.