@digital-realty/ui-user-management
Webcomponent ui-user-management following open-wc recommendations
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:pnpm | AI (phantom-deps): pnpm used as build tool via scripts, not imported; expected for this monorepo. | ai | |
| provenance | missing-githead | AI (provenance): No malicious behavior tied to publish env change; internal CI variance. | ai | |
| phantom-deps | phantom-dep:mobx | AI (phantom-deps): Same pattern — declared peer dep, not directly imported in dist. | ai | |
| source-diff | obfuscated-file:dist/workbox-b865b753.js | AI (source-diff): Workbox 6.5.4 service worker bundle — standard minified build output from rollup-plugin-workbox, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@graphql-typed-document-node/core | AI (phantom-deps): Newly added dep for GraphQL codegen; declared but consumed via generated code, stable false positive. | ai | |
| phantom-deps | phantom-dep:graphql | AI (phantom-deps): Same pattern — declared peer dep, not directly imported in dist. | ai | |
| phantom-deps | phantom-dep:lit | AI (phantom-deps): Monorepo UI library; peer/workspace deps declared in package.json but consumed via bundled dist. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 12.0.10 | 58 / 51 | |
| 12.0.8 | 57 / 51 | |
| 12.0.7 | 57 / 50 | |
| 12.0.3 | 57 / 50 | |
| 12.0.2 | 57 / 50 | |
| 12.0.1 | 57 / 50 | |
| 11.0.0 | 56 / 50 |
v12.0.10
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dlr-pi-devops.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.0.8
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dlr-pi-devops.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.