@digital-realty/ui-service-management
Webcomponent ui-service-management following open-wc recommendations
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): Config-referenced dep, stable FP. | ai | |
| phantom-deps | phantom-dep:@digital-realty/grid | AI (phantom-deps): Same-org component dep, expected pattern for this monorepo package. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): Config-referenced dep, stable FP. | ai | |
| source-diff | obfuscated-file:dist/workbox-b865b753.js | AI (source-diff): Known Workbox library minified build, not attacker-injected obfuscation. | ai | |
| phantom-deps | phantom-dep:mobx | AI (phantom-deps): Legit dep used indirectly via config in this design-system package. | ai | |
| source-diff | obfuscated-file:dist/workbox-a523fd56.js | AI (source-diff): Google Workbox service-worker bundle, minified build output not malicious obfuscation. | ai | |
| phantom-deps | phantom-dep:lit | AI (phantom-deps): Used via templates/config in this monorepo build, common false positive. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): New dep likely used in generated/config code not statically detected. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 12.6.4 | 51 / 50 | |
| 12.6.1 | 50 / 49 | |
| 12.0.17 | 51 / 50 | |
| 12.0.13 | 51 / 50 | |
| 12.0.3 | 50 / 49 | |
| 11.0.4 | 50 / 49 | |
| 11.0.3 | 50 / 49 | |
| 11.0.0 | 50 / 49 |
v12.6.4
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dlr-pi-devops.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.6.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.0.17
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dlr-pi-devops.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.