@dr.pogodin/react-utils
Collection of generic ReactJS components and utils
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): CI-based publisher label with unchanged provenance direction; not a compromise indicator. | ai | |
| phantom-deps | phantom-dep:@dr.pogodin/babel-plugin-react-css-modules | AI (phantom-deps): Same-org babel plugin used in build config, not direct import. | ai | |
| phantom-deps | phantom-dep:autoprefix | AI (phantom-deps): Likely used in build pipeline, not source imports. | ai | |
| phantom-deps | phantom-dep:url-parse | AI (phantom-deps): Plausible runtime use missed by static import scan. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Likely used in bin scripts, not scanned by heuristic. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Standard patch-package postinstall, present in devDeps, non-executing fallback. | ai | |
| phantom-deps | phantom-dep:@babel/runtime-corejs3 | AI (phantom-deps): Framework-scoped runtime helper loaded by convention, not direct import. | ai | |
| semgrep | semgrep:child-process-exec | AI (semgrep): exec() in bin/build.js is part of the documented build CLI; not a runtime or install-time risk. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process is used in the CLI build script (bin/build.js); expected for a build toolchain package. | ai | |
| source-diff | obfuscated-file:build/development/web.bundle.js | AI (source-diff): Standard webpack development bundle using eval devtool; explicitly documented in the file header. | ai | |
| source-diff | net-exec-file:build/development/web.bundle.js | AI (source-diff): eval() usage is webpack's eval devtool for source maps, not malicious code execution. | ai | |
| source-diff | obfuscated-file:build/production/web.bundle.js | AI (source-diff): Standard webpack production minified bundle; not obfuscation, just minification. | ai | |
| source-diff | net-exec-file:build/production/web.bundle.js | AI (source-diff): Network calls and dynamic code in webpack bundle are from bundled legitimate deps (axios, node-forge), not malware. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() used to parse server-injected data; commented with TODO for safer alternative, not malicious. | ai | |
| phantom-deps | phantom-dep:rimraf | AI (phantom-deps): Used in build scripts only, not imported at runtime; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@commander-js/extra-typings | AI (phantom-deps): TypeScript types package referenced in config, not a runtime import; stable false positive. | ai | |
| dependencies | unvetted-dep:@dr.pogodin/react-global-state | AI (dependencies): First-party package from same author. | ai | |
| dependencies | unvetted-dep:@dr.pogodin/react-themes | AI (dependencies): First-party package from same author. | ai | |
| dependencies | unvetted-dep:@dr.pogodin/react-helmet | AI (dependencies): First-party package from same author. | ai | |
| dependencies | unvetted-dep:@dr.pogodin/csurf | AI (dependencies): First-party package from same author; consistent pattern across all versions. | ai | |
| dependencies | unvetted-dep:@dr.pogodin/js-utils | AI (dependencies): First-party package from same author. | ai | |
| dependencies | unvetted-dep:@dr.pogodin/babel-plugin-react-css-modules | AI (dependencies): First-party package from same author. | ai | |
| typosquat | typosquat.pattern:react | AI (typosquat): Scoped package under author's own namespace; not impersonating react. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:cross-env | AI (phantom-deps): cross-env is a declared runtime dep used in config/scripts, not directly imported in JS — stable false positive. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads user-specified webpack config file; documented CLI build tool behavior. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env-spread in build CLI script passing env to child process; standard build tool pattern, not a secret leak. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped package loaded by Babel transform convention, not directly imported. | ai |
Versions (showing 51 of 333)
| Version | Deps | Published |
|---|---|---|
| 1.55.0 | 34 / 76 | |
| 1.54.3 | 34 / 77 | |
| 1.54.2 | 34 / 77 | |
| 1.54.1 | 34 / 77 | |
| 1.54.0 | 34 / 77 | |
| 1.53.1 | 34 / 75 | |
| 1.53.0 | 34 / 75 | |
| 1.52.11 | 34 / 75 | |
| 1.52.10 | 34 / 75 | |
| 1.52.9 | 34 / 75 | |
| 1.52.8 | 34 / 75 | |
| 1.52.7 | 34 / 75 | |
| 1.52.6 | 34 / 75 | |
| 1.52.5 | 34 / 75 | |
| 1.52.4 | 34 / 75 | |
| 1.52.3 | 34 / 75 | |
| 1.52.2 | 34 / 75 | |
| 1.52.1 | 34 / 75 | |
| 1.52.0 | 34 / 75 | |
| 1.51.4 | 34 / 75 | |
| 1.51.3 | 34 / 75 | |
| 1.51.2 | 35 / 75 | |
| 1.51.1 | 35 / 75 | |
| 1.51.0 | 35 / 75 | |
| 1.50.2 | 35 / 74 | |
| 1.50.1 | 35 / 74 | |
| 1.50.0 | 35 / 74 | |
| 1.49.1 | 34 / 74 | |
| 1.49.0 | 34 / 74 | |
| 1.48.20 | 34 / 74 | |
| 1.48.19 | 34 / 74 | |
| 1.48.18 | 34 / 74 | |
| 1.48.17 | 34 / 74 | |
| 1.48.16 | 34 / 74 | |
| 1.48.15 | 34 / 74 | |
| 1.48.14 | 34 / 74 | |
| 1.48.13 | 34 / 74 | |
| 1.48.12 | 34 / 74 | |
| 1.48.10 | 34 / 74 | |
| 1.48.9 | 34 / 74 | |
| 1.48.8 | 34 / 74 | |
| 1.48.7 | 34 / 74 | |
| 1.48.6 | 34 / 74 | |
| 1.48.5 | 34 / 74 | |
| 1.48.4 | 34 / 74 | |
| 1.48.3 | 34 / 74 | |
| 1.48.2 | 34 / 74 | |
| 1.48.1 | 34 / 74 | |
| 1.48.0 | 34 / 74 | |
| 1.47.5 | 34 / 74 | |
| 1.47.4 | 34 / 74 |
v1.55.0
3 findingsScript: patch-package || true
This version was published by a different npm account than previous versions on 2026-07-26. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.54.3
2 findingsThis version was published by a different npm account than previous versions on 2026-07-08. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.54.2
2 findingsThis version was published by a different npm account than previous versions on 2026-06-25. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.54.1
2 findingsThis version was published by a different npm account than previous versions on 2026-06-21. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.54.0
2 findingsThis version was published by a different npm account than previous versions on 2026-06-21. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.1
2 findingsThis version was published by a different npm account than previous versions on 2026-06-18. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.0
2 findingsThis version was published by a different npm account than previous versions on 2026-06-07. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.52.11
2 findingsThis version was published by a different npm account than previous versions on 2026-06-03. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.52.10
2 findingsThis version was published by a different npm account than previous versions on 2026-06-02. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.52.9
2 findingsThis version was published by a different npm account than previous versions on 2026-05-27. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.52.8
2 findingsThis version was published by a different npm account than previous versions on 2026-05-26. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.52.7
2 findingsThis version was published by a different npm account than previous versions on 2026-05-21. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.