@codebit-programando-solucoes/codebit-web-antd
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index.cjs | AI (source-diff): Bundled webpack/rspack output with visible React license headers, not true obfuscation. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a peer/runtime dep for a React component library; indirect usage is expected. | ai | |
| phantom-deps | phantom-dep:sass | AI (phantom-deps): sass is used via @rsbuild/plugin-sass build tooling, not directly imported in source; stable false positive for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Low-effort metadata but legitimate scoped internal UI library, no malicious behavior. | ai |
v1.1.41
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (bogus-package): Empty description, no repo/homepage/bugs, no keywords—pattern consistent with low-value/spam packages.) Matched 3 signal(s), weighted score 3: • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.