@djangocfg/ui-tools
Heavy React tools with lazy loading - for Electron, Vite, CRA, Next.js apps
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:src/tools/visual/design/FileIcon/icons/icon-data.ts | AI (source-diff): Auto-generated static SVG icon data module; long lines are inline SVG strings, not obfuscation. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/sortable | AI (phantom-deps): Used via re-exports/config; stable false positive for this UI toolkit. | ai | |
| phantom-deps | phantom-dep:@types/qrcode | AI (phantom-deps): Type-only dep; not imported at runtime by design. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-bubble-menu | AI (phantom-deps): Tiptap extensions loaded via config/re-export; stable false positive. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/utilities | AI (phantom-deps): Same pattern as other dnd-kit deps; stable false positive. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/modifiers | AI (phantom-deps): Same pattern as other dnd-kit deps; stable false positive. | ai | |
| source-diff | obfuscated-file:src/tools/Chat/core/audio/sounds/notification.ts | AI (source-diff): Base64-encoded MP3 audio asset inlined as data URL; documented pattern, not obfuscated code. | ai | |
| source-diff | obfuscated-file:src/tools/Chat/core/audio/sounds/mention.ts | AI (source-diff): Base64-encoded MP3 audio asset inlined as data URL; documented pattern, not obfuscated code. | ai | |
| source-diff | obfuscated-file:src/tools/Chat/core/audio/sounds/received.ts | AI (source-diff): Base64-encoded MP3 audio asset inlined as data URL; documented pattern, not obfuscated code. | ai | |
| source-diff | obfuscated-file:src/tools/Chat/core/audio/sounds/start.ts | AI (source-diff): Base64-encoded MP3 audio asset inlined as data URL; documented pattern, not obfuscated code. | ai | |
| source-diff | obfuscated-file:src/tools/FileIcon/icons/icon-data.ts | AI (source-diff): Auto-generated vendored SVG icon data from material-file-icons (MIT); comment confirms provenance. | ai | |
| source-diff | obfuscated-file:src/tools/Chat/core/audio/sounds/error.ts | AI (source-diff): Base64-encoded MP3 audio asset inlined as data URL; comment and content confirm legitimate use. | ai | |
| phantom-deps | phantom-dep:wavesurfer.js | AI (phantom-deps): Same re-export/config pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:vidstack | AI (phantom-deps): Declared as dependency for re-export/config use; stable pattern for this multi-tool package. | ai | |
| phantom-deps | phantom-dep:@wavesurfer/react | AI (phantom-deps): Same re-export/config pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tiptap/pm | AI (phantom-deps): Tiptap peer dep used indirectly; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:media-icons | AI (phantom-deps): Same re-export/config pattern; stable false positive for this package. | ai |
Versions (showing 51 of 343)
| Version | Deps | Published |
|---|---|---|
| 2.1.490 | 61 / 18 | |
| 2.1.489 | 61 / 18 | |
| 2.1.488 | 61 / 18 | |
| 2.1.487 | 61 / 18 | |
| 2.1.486 | 61 / 18 | |
| 2.1.484 | 61 / 18 | |
| 2.1.483 | 61 / 18 | |
| 2.1.482 | 61 / 18 | |
| 2.1.481 | 61 / 18 | |
| 2.1.480 | 61 / 18 | |
| 2.1.479 | 61 / 18 | |
| 2.1.478 | 61 / 18 | |
| 2.1.477 | 61 / 18 | |
| 2.1.476 | 61 / 18 | |
| 2.1.475 | 61 / 18 | |
| 2.1.474 | 61 / 18 | |
| 2.1.472 | 61 / 18 | |
| 2.1.471 | 61 / 18 | |
| 2.1.470 | 61 / 18 | |
| 2.1.469 | 61 / 18 | |
| 2.1.468 | 61 / 18 | |
| 2.1.466 | 61 / 18 | |
| 2.1.465 | 61 / 18 | |
| 2.1.464 | 61 / 18 | |
| 2.1.463 | 61 / 18 | |
| 2.1.462 | 61 / 18 | |
| 2.1.460 | 61 / 18 | |
| 2.1.459 | 61 / 18 | |
| 2.1.457 | 61 / 18 | |
| 2.1.456 | 61 / 18 | |
| 2.1.455 | 61 / 18 | |
| 2.1.454 | 61 / 18 | |
| 2.1.453 | 61 / 18 | |
| 2.1.452 | 61 / 18 | |
| 2.1.450 | 61 / 18 | |
| 2.1.449 | 61 / 18 | |
| 2.1.448 | 61 / 18 | |
| 2.1.447 | 61 / 18 | |
| 2.1.446 | 61 / 18 | |
| 2.1.445 | 61 / 18 | |
| 2.1.444 | 61 / 18 | |
| 2.1.443 | 61 / 18 | |
| 2.1.442 | 61 / 18 | |
| 2.1.441 | 61 / 18 | |
| 2.1.440 | 61 / 18 | |
| 2.1.439 | 61 / 18 | |
| 2.1.438 | 61 / 18 | |
| 2.1.437 | 61 / 18 | |
| 2.1.436 | 61 / 18 | |
| 2.1.435 | 61 / 18 | |
| 2.1.434 | 61 / 18 |
v2.1.490
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.489
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.488
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.487
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.486
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.484
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.483
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.482
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.481
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.480
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.479
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.478
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.477
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.476
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.475
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.474
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.472
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.471
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.470
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.469
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.468
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.466
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.465
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.464
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.463
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.462
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.460
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.459
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.457
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.456
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.455
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.454
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.453
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.452
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.450
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.449
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.448
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.447
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.446
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.445
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.444
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.443
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.442
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.441
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.