← Home

@codefast/ui

Core UI components library built with React and Tailwind CSS

38
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

thevuong

Keywords

componentsdesign-systemmonoreporadix-uireacttailwindtailwindcsstypescriptui

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/components/context-menu.cjs AI (source-diff): tsup-bundled CJS output, not true obfuscation. ai
source-diff obfuscated-file:dist/components/command.cjs AI (source-diff): tsup-bundled CJS output, not true obfuscation. ai
source-diff obfuscated-file:dist/components/carousel.cjs AI (source-diff): tsup-bundled CJS output, not true obfuscation. ai
source-diff obfuscated-file:dist/components/calendar.cjs AI (source-diff): tsup-bundled CJS output, not true obfuscation. ai
source-diff obfuscated-file:dist/components/alert-dialog.cjs AI (source-diff): tsup-bundled CJS output, not true obfuscation. ai
source-diff obfuscated-file:dist/components/input-otp.cjs AI (source-diff): tsup-bundled CJS output, not true obfuscation. ai
source-diff obfuscated-file:dist/components/form.cjs AI (source-diff): tsup-bundled CJS output, not true obfuscation. ai
source-diff obfuscated-file:dist/components/data-table.cjs AI (source-diff): tsup-bundled CJS output, not true obfuscation. ai
dependencies unvetted-dep:@codefast-ui/number-input AI (dependencies): Same-org monorepo sibling pinned to identical version. ai
dependencies unvetted-dep:@codefast-ui/checkbox-group AI (dependencies): Same-org monorepo sibling pinned to identical version. ai
source-diff obfuscated-file:dist/tailwindcss/animate.cjs AI (source-diff): Minified tailwindcss plugin build output, not true obfuscation. ai
dependencies unvetted-dep:@codefast-ui/input AI (dependencies): Same-org monorepo sibling pinned to identical version. ai
dependencies unvetted-dep:@codefast-ui/day-picker AI (dependencies): Same-org monorepo sibling pinned to identical version. ai
source-diff obfuscated-file:dist/lib/colors.js AI (source-diff): Minified color-token data table with matching sourcemap, not obfuscation. ai
source-diff obfuscated-file:dist/lib/colors.mjs AI (source-diff): Same colors data file, ESM build output. ai
bogus-package bogus-package AI (bogus-package): Established UI library with long history; missing description/repo is cosmetic. ai
source-diff large-new-source-files AI (source-diff): Matches large multi-component UI library export surface. ai
source-diff obfuscated-file:dist/react/context-menu.cjs AI (source-diff): Bundled build artifact matching radix wrapper source. ai
source-diff obfuscated-file:dist/react/alert-dialog.cjs AI (source-diff): tsup/esbuild bundled output, not obfuscation; matches source component. ai
source-diff obfuscated-file:dist/react/carousel.cjs AI (source-diff): Bundled build artifact, standard interop helpers. ai
source-diff obfuscated-file:dist/lib/colors.cjs AI (source-diff): Static color palette data, minified not obfuscated. ai
source-diff obfuscated-file:dist/react/command.cjs AI (source-diff): Bundled build artifact matching cmdk wrapper source. ai
source-diff obfuscated-file:dist/react/data-table.cjs AI (source-diff): Bundled build artifact, standard table component code. ai
source-diff obfuscated-file:dist/react/form.cjs AI (source-diff): Bundled build artifact matching react-hook-form wrapper. ai
source-diff obfuscated-file:dist/react/input-otp.cjs AI (source-diff): Bundled build artifact matching input-otp wrapper. ai
phantom-deps phantom-dep:@radix-ui/react-direction AI (phantom-deps): Radix direction is a transitive peer used via config; not directly imported but legitimately referenced. ai
dependencies unvetted-dep:@radix-ui/react-hover-card AI (dependencies): @radix-ui/react-hover-card is a well-known, widely-used primitive; stable false positive for this UI library. ai
dependencies unvetted-dep:@radix-ui/react-avatar AI (dependencies): @radix-ui/react-avatar is a well-known, widely-used primitive; stable false positive for this UI library. ai
phantom-deps phantom-dep:date-fns AI (phantom-deps): date-fns is a legitimate runtime dep used by the calendar component via react-day-picker; phantom-dep is a false positive here. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped UI component library; not a typosquat of qs. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): Scoped UI component library; not a typosquat of uuid. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped UI component library; not a typosquat of pg. ai
phantom-deps phantom-dep:tw-animate-css AI (phantom-deps): tw-animate-css is a CSS-only dep referenced in config files, not JS imports; phantom-dep false positive for this package. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped UI component library; not a typosquat of yup. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped UI component library; not a typosquat of joi. ai

Versions (showing 38 of 38)

Version Deps Published
0.4.0 14 / 18
0.3.15 46 / 17
0.3.14 46 / 17
0.3.13 46 / 17
0.3.12 47 / 19
0.3.11 47 / 19
0.3.10 47 / 22
0.3.9 47 / 22
0.3.8 47 / 22
0.3.1 48 / 22
0.2.20 48 / 10
0.1.28 46 / 10
0.1.16 48 / 13
0.1.3 48 / 12
0.0.66 48 / 12
0.0.64 47 / 12
0.0.63 46 / 12
0.0.62 46 / 12
0.0.61 46 / 12
0.0.60 46 / 12
0.0.59 46 / 12
0.0.58 46 / 12
0.0.57 46 / 12
0.0.56 46 / 12
0.0.55 46 / 12
0.0.54 46 / 12
0.0.53 46 / 12
0.0.52 46 / 12
0.0.50 46 / 12
0.0.49 46 / 12
0.0.48 46 / 12
0.0.47 46 / 12
0.0.46 46 / 12
0.0.45 46 / 12
0.0.44 46 / 12
0.0.43 46 / 12
0.0.42 46 / 12
0.0.41 46 / 12

v0.3.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.20

2 findings
HIGH New obfuscated file: dist/tailwindcss/animate.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.16

11 findings
HIGH New obfuscated file: dist/components/alert-dialog.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/calendar.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/carousel.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/command.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/context-menu.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/data-table.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/form.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/input-otp.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/menubar.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/navigation-menu.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

11 findings
HIGH New obfuscated file: dist/react/alert-dialog.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/calendar.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/carousel.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/command.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/context-menu.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/data-table.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/form.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/input-otp.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/menubar.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/navigation-menu.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.66

9 findings
HIGH New obfuscated file: dist/react/alert-dialog.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/carousel.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/lib/colors.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/command.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/context-menu.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/data-table.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/form.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/input-otp.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.64

10 findings
HIGH New obfuscated file: dist/react/alert-dialog.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/carousel.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/lib/colors.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/command.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/context-menu.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/data-table.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/form.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/input-otp.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react/menubar.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.63

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.62

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.61

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.60

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.54

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.53

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.52

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.50

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.49

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.48

3 findings
HIGH New obfuscated file: dist/lib/colors.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/lib/colors.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.47

3 findings
HIGH New obfuscated file: dist/lib/colors.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/lib/colors.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.46

3 findings
HIGH New obfuscated file: dist/lib/colors.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/lib/colors.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.45

3 findings
HIGH New obfuscated file: dist/lib/colors.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/lib/colors.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.44

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.