@descope/web-components-ui
Descope Web Components UI Library
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@descope-ui/descope-honeypot | AI (phantom-deps): Used via config/registration pattern typical of web-components suites, not a real phantom dep. | ai | |
| dependencies | unvetted-dep:@descope-ui/descope-honeypot | AI (dependencies): First-party sibling package in same monorepo, version-locked with rest of suite. | ai | |
| source-diff | obfuscated-file:dist/umd/67.js | AI (source-diff): Webpack-bundled UMD chunk, banner confirms build output not obfuscation. | ai | |
| dependencies | unvetted-dep:@descope-ui/descope-filter | AI (dependencies): Same-org monorepo sibling package, consistent with existing dependency pattern. | ai | |
| source-diff | obfuscated-file:dist/umd/descope-filter.js | AI (source-diff): Webpack-bundled UMD chunk, banner confirms build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/umd/9439.js | AI (source-diff): Webpack-bundled UMD chunk, banner confirms build output not obfuscation. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Cosmetic metadata gap, consistent across Descope monorepo packages. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Spam heuristics from missing description/repo fields, not actual spam. | ai | |
| dependencies | unvetted-dep:@descope-ui/descope-month-day-field | AI (dependencies): First-party @descope-ui monorepo package pinned to same version. | ai | |
| dependencies | unvetted-dep:@descope-ui/descope-month-day-field-picker | AI (dependencies): First-party @descope-ui monorepo package pinned to same version. | ai | |
| source-diff | obfuscated-file:dist/umd/descope-multi-sso.js | AI (source-diff): Standard webpack UMD bundle; minification is expected for this package's dist output. | ai | |
| source-diff | obfuscated-file:dist/umd/9265.js | AI (source-diff): Standard webpack UMD bundle from Descope's own build pipeline; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/umd/6618.js | AI (source-diff): Standard webpack UMD bundle from Descope's own build pipeline; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/umd/8350.js | AI (source-diff): Standard webpack UMD bundle from Descope's own build pipeline; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/umd/descope-month-day-field-picker.js | AI (source-diff): Standard webpack UMD bundle for new first-party Descope component; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/umd/descope-month-day-field.js | AI (source-diff): Standard webpack UMD bundle for new first-party Descope component; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/umd/descope-text-field.js | AI (source-diff): Standard webpack UMD bundle for new first-party Descope component; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/umd/descope-user-passkeys.js | AI (source-diff): Standard webpack UMD bundle with license header; matches existing build pattern for all other component bundles in this package. | ai | |
| phantom-deps | phantom-dep:@descope-ui/descope-anchored | AI (phantom-deps): Referenced in config files as expected for monorepo component; not a real phantom dep. | ai | |
| dependencies | unvetted-dep:@descope-ui/descope-outbound-app-button | AI (dependencies): Internal @descope-ui scoped sibling; consistent monorepo versioning pattern. | ai | |
| dependencies | unvetted-dep:@descope-ui/descope-image | AI (dependencies): Internal @descope-ui scoped sibling; consistent monorepo versioning pattern across all releases. | ai | |
| dependencies | unvetted-dep:@descope-ui/descope-anchored | AI (dependencies): Newly added internal @descope-ui scoped sibling; fits established monorepo pattern. | ai | |
| dependencies | unvetted-dep:@descope-ui/descope-ponyhot | AI (dependencies): Internal @descope-ui scoped sibling; consistent monorepo versioning pattern. | ai | |
| phantom-deps | phantom-dep:@descope-ui/descope-ponyhot | AI (phantom-deps): Monorepo sibling package; declared in package.json as a runtime dep, config-only reference is expected. | ai | |
| source-diff | obfuscated-file:dist/umd/descope-multi-line-mappings.js | AI (source-diff): Standard webpack-minified UMD bundle for new @descope-ui/descope-multi-line-mappings component. | ai | |
| source-diff | obfuscated-file:stories/icons/base64svg.js | AI (source-diff): Inline base64 data URI for SVG icon asset; not executable obfuscation. | ai | |
| source-diff | obfuscated-file:stories/helpers.js | AI (source-diff): Plain readable JS Storybook helper; long lines are template literals, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/umd/descope-multi-select-combo-box.js | AI (source-diff): Standard webpack-minified UMD bundle for new @descope-ui/descope-multi-select-combo-box component. | ai | |
| source-diff | obfuscated-file:stories/icons/base64png.js | AI (source-diff): Inline base64 data URI for PNG icon asset; not executable obfuscation. | ai | |
| source-diff | obfuscated-file:dist/umd/descope-anchored.js | AI (source-diff): Standard webpack-minified UMD bundle for new @descope-ui/descope-anchored component. | ai |
Versions (showing 35 of 135)
| Version | Deps | Published |
|---|---|---|
| 2.2.43 | 46 / 43 | |
| 2.2.42 | 46 / 43 | |
| 2.2.41 | 46 / 43 | |
| 2.2.40 | 46 / 43 | |
| 2.2.39 | 46 / 43 | |
| 2.2.38 | 46 / 43 | |
| 2.2.37 | 46 / 43 | |
| 2.2.35 | 46 / 43 | |
| 2.2.34 | 46 / 43 | |
| 2.2.31 | 46 / 43 | |
| 2.2.28 | 46 / 43 | |
| 2.2.26 | 45 / 43 | |
| 2.2.25 | 45 / 43 | |
| 2.2.24 | 45 / 43 | |
| 2.2.23 | 45 / 43 | |
| 2.2.22 | 45 / 43 | |
| 2.2.21 | 45 / 43 | |
| 2.2.20 | 45 / 43 | |
| 2.2.19 | 45 / 43 | |
| 2.2.18 | 45 / 43 | |
| 2.2.17 | 45 / 43 | |
| 2.2.16 | 45 / 43 | |
| 2.2.15 | 45 / 43 | |
| 2.2.14 | 45 / 43 | |
| 2.2.13 | 45 / 43 | |
| 2.2.12 | 44 / 43 | |
| 2.2.11 | 44 / 43 | |
| 2.2.10 | 44 / 43 | |
| 2.2.9 | 44 / 43 | |
| 2.2.8 | 44 / 43 | |
| 2.2.7 | 44 / 43 | |
| 2.2.6 | 44 / 43 | |
| 2.2.5 | 44 / 43 | |
| 2.2.4 | 44 / 43 | |
| 2.2.3 | 44 / 43 |
v2.2.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.42
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.