@dxtmisha/d1
DXT-UI component library
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Active UI component library; new files reflect legitimate component additions, not injected payloads. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size growth matches the number of new exported components; consistent with organic library expansion. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps are same-org @dxtmisha/* scoped packages, not third-party supply-chain risk. | ai | |
| phantom-deps | phantom-dep:@dxtmisha/styles | AI (phantom-deps): Same-org monorepo dep; may be used indirectly or re-exported without direct import. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package @dxtmisha/d1 cannot typosquat unscoped 'pg'; edit-distance match is spurious. | ai | |
| phantom-deps | phantom-dep:@dxtmisha/configuration | AI (phantom-deps): Same-org monorepo dep; may be used indirectly or re-exported without direct import. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped package @dxtmisha/d1 cannot typosquat unscoped 'qs'; edit-distance match is spurious. | ai | |
| phantom-deps | phantom-dep:@dxtmisha/media | AI (phantom-deps): Same-org monorepo dep; may be used indirectly or re-exported without direct import. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 0.68.0 | 0 / 0 | |
| 0.67.2 | 0 / 0 | |
| 0.67.0 | 0 / 0 | |
| 0.65.1 | 0 / 0 | |
| 0.65.0 | 0 / 0 | |
| 0.64.0 | 0 / 0 | |
| 0.59.3 | 0 / 0 | |
| 0.59.1 | 0 / 0 | |
| 0.59.0 | 0 / 0 | |
| 0.57.3 | 7 / 0 | |
| 0.57.1 | 7 / 0 | |
| 0.57.0 | 7 / 0 | |
| 0.52.3 | 6 / 0 | |
| 0.52.2 | 6 / 0 | |
| 0.52.1 | 6 / 0 | |
| 0.52.0 | 6 / 0 | |
| 0.2.0 | 6 / 0 | |
| 0.1.5 | 5 / 0 | |
| 0.1.3 | 0 / 0 | |
| 0.1.2 | 7 / 0 | |
| 0.1.1 | 7 / 0 | |
| 0.1.0 | 0 / 7 |
v0.68.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.67.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.67.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.65.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.65.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.64.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.59.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.59.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.59.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.57.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.52.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.52.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.52.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.52.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.