← Home

@dialpad/dialtone

Dialpad's Dialtone design system monorepo

6
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

braddialpadjadialpadjawreyjuliodialpad

Keywords

DialpadDialtoneDialtone VueDialtone IconsDialtone TokensDesign SystemComponentsComponent Library

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/vue3/message_input-BiCHkV9g.cjs AI (source-diff): Standard Vite/Rollup minified CJS bundle output; code samples show normal Vue/Tiptap component logic, not malicious code. ai
source-diff obfuscated-file:dist/vue3/rich_text_editor-FduHYl-G.cjs AI (source-diff): Standard Vite/Rollup minified CJS bundle output; code samples show normal Tiptap editor extensions, not malicious code. ai
dependencies unvetted-dep:docopt AI (dependencies): Known CLI argument parsing library; stable dependency for this design system tooling. ai
dependencies unvetted-dep:@dialpad/i18n AI (dependencies): First-party @dialpad scoped package; consistent with this design system's ecosystem. ai
dependencies unvetted-dep:emoji-toolkit AI (dependencies): Known emoji rendering library; expected dependency for a component library with emoji support. ai
dependencies unvetted-dep:regex-combined-emojis AI (dependencies): Emoji regex utility; expected for a component library with rich text/emoji features. ai
dependencies unvetted-dep:@dialpad/dialtone-mcp-server AI (dependencies): First-party @dialpad scoped package; consistent with this design system's ecosystem. ai
phantom-deps phantom-dep:globals AI (phantom-deps): Config-file-only reference in a design system monorepo; stable false positive. ai
phantom-deps phantom-dep:vue-tsc AI (phantom-deps): Config-file-only reference; stable false positive for this package. ai
phantom-deps phantom-dep:linkifyjs AI (phantom-deps): Config-file-only reference; stable false positive for this package. ai
phantom-deps phantom-dep:@floating-ui/dom AI (phantom-deps): Config-file-only reference; stable false positive for this package. ai
phantom-deps phantom-dep:@tiptap/extension-color AI (phantom-deps): Config-file-only reference; stable false positive for this package. ai
phantom-deps phantom-dep:@dialpad/dialtone-tokens AI (phantom-deps): Same-org dep; stable false positive for this package. ai
phantom-deps phantom-dep:@dialpad/dialtone-mcp-server AI (phantom-deps): Same-org dep; stable false positive for this package. ai
phantom-deps phantom-dep:@tiptap/extension-bubble-menu AI (phantom-deps): Config-file-only reference; stable false positive for this package. ai
phantom-deps phantom-dep:@tiptap/extension-font-family AI (phantom-deps): Config-file-only reference; stable false positive for this package. ai
phantom-deps phantom-dep:@tiptap/extension-floating-menu AI (phantom-deps): Config-file-only reference; stable false positive for this package. ai

Versions (showing 6 of 6)

Version Deps Published
9.186.0 42 / 64
9.185.0 42 / 64
9.184.0 42 / 64
9.183.0 42 / 64
9.182.3 42 / 64
9.182.1 42 / 64

v9.186.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.185.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.184.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.183.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.182.3

3 findings
HIGH New obfuscated file: dist/vue3/message_input-BiCHkV9g.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/vue3/rich_text_editor-FduHYl-G.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.182.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.