← Home

@danske/sapphire-react-lab

Experimental React components of the Sapphire Design System from Danske Bank A/S

24
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

tgelu-db

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@danske/sapphire-css AI (dependencies): Internal sibling package from the same Danske Bank org; stable across versions. ai
phantom-deps phantom-dep:@react-types/dialog AI (phantom-deps): Type-only reference in component library; stable false positive. ai
phantom-deps phantom-dep:@react-stately/toggle AI (phantom-deps): react-stately config reference; stable false positive for this package. ai
phantom-deps phantom-dep:@react-stately/combobox AI (phantom-deps): react-stately config reference; stable false positive for this package. ai
phantom-deps phantom-dep:@react-stately/overlays AI (phantom-deps): react-stately config reference; stable false positive for this package. ai
phantom-deps phantom-dep:@react-aria/dialog AI (phantom-deps): react-aria packages declared for type/config use in component library; stable pattern for this package. ai
phantom-deps phantom-dep:@react-stately/tree AI (phantom-deps): Same pattern — react-stately config/type reference in component library build. ai
phantom-deps phantom-dep:@react-aria/overlays AI (phantom-deps): react-aria config reference; stable false positive for this package. ai
bogus-package bogus-package AI (bogus-package): Internal org-scoped design system package; sparse README and no public repo/keywords are expected for private/internal packages. ai
phantom-deps phantom-dep:@internationalized/date AI (phantom-deps): Listed as direct dependency in package.json; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@internationalized/string AI (phantom-deps): Listed as direct dependency in package.json; phantom-dep heuristic false positive for this package. ai

Versions (showing 24 of 24)

Version Deps Published
0.106.3 11 / 4
0.106.2 13 / 4
0.106.1 36 / 4
0.105.2 36 / 4
0.104.0 36 / 4
0.103.0 36 / 4
0.102.0 34 / 4
0.101.2 34 / 4
0.101.1 34 / 4
0.101.0 34 / 4
0.100.0 33 / 4
0.99.3 31 / 4
0.99.2 31 / 4
0.99.1 31 / 4
0.99.0 31 / 4
0.98.0 31 / 4
0.97.0 30 / 4
0.96.3 29 / 4
0.96.2 29 / 4
0.96.1 29 / 4
0.96.0 29 / 4
0.95.3 29 / 4
0.95.2 29 / 4
0.95.1 29 / 4

v0.106.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.106.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.105.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.104.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.103.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.102.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.101.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.101.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.101.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.100.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.99.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.99.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.99.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.99.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.98.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.97.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.96.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.96.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.96.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.96.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.95.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.95.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.95.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.