@dynatrace/strato-components
These reusable React components are the building blocks for Dynatrace. Use them in line with Strato's design foundations and patterns to create great Dynatrace experiences. See [About Strato](https://developer.dynatrace.com/design/about-strato-design-syst
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): All well-known UI/build ecosystem packages consistent with component library growth. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Explained by legitimate new dependency tree, not injected payload. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected from skipped intermediate versions adding many new components/deps. | ai | |
| source-diff | obfuscated-file:migrations/3.2.0/dt-app-migration.js | AI (source-diff): Explicitly declared migration factory in package.json; minified bundle is expected for this codemod. | ai | |
| source-diff | net-exec-file:migrations/3.2.0/codeshift-migration.js | AI (source-diff): False positive on bundled codemod; tslib/jscodeshift bundle pattern, not dropper malware. | ai | |
| source-diff | obfuscated-file:migrations/3.2.0/codeshift-migration.js | AI (source-diff): Bundled jscodeshift codemod; minified output is expected and declared in package.json dt.migrations. | ai | |
| dependencies | unvetted-dep:@dynatrace-sdk/segments-presets | AI (dependencies): First-party Dynatrace SDK package; consistent with this package's ecosystem and publisher identity. | ai | |
| phantom-deps | phantom-dep:@vanilla-extract/dynamic | AI (phantom-deps): Referenced in config files only; consistent with vanilla-extract build pattern for this package. | ai | |
| phantom-deps | phantom-dep:@dynatrace/devkit | AI (phantom-deps): Same org build tooling; stable false positive for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): No material changes from prior approved version; established Dynatrace package with clean publisher history. | ai | |
| phantom-deps | phantom-dep:type-fest | AI (phantom-deps): Large UI component library; type-only deps referenced in config files are a stable false positive pattern. | ai | |
| phantom-deps | phantom-dep:@formatjs/icu-messageformat-parser | AI (phantom-deps): i18n parser referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@vanilla-extract/css | AI (phantom-deps): vanilla-extract CSS-in-JS referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:identity-obj-proxy | AI (phantom-deps): Test utility referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/utilities | AI (phantom-deps): dnd-kit packages referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/modifiers | AI (phantom-deps): dnd-kit packages referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:d3-interpolate | AI (phantom-deps): d3 packages used in chart config/type files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@visx/event | AI (phantom-deps): visx packages used in chart config/type files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@visx/brush | AI (phantom-deps): visx packages used in chart config/type files; stable false positive for this package. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 3.9.0 | 65 / 0 | |
| 3.8.0 | 66 / 0 | |
| 3.7.2 | 71 / 0 | |
| 3.7.1 | 71 / 0 | |
| 3.7.0 | 71 / 0 | |
| 3.6.1 | 72 / 0 | |
| 3.6.0 | 72 / 0 | |
| 3.5.3 | 72 / 0 | |
| 3.5.2 | 72 / 0 | |
| 3.5.0 | 72 / 0 | |
| 3.4.1 | 72 / 0 | |
| 3.4.0 | 72 / 0 | |
| 3.3.3 | 72 / 0 | |
| 3.3.2 | 72 / 0 | |
| 3.3.1 | 72 / 0 | |
| 3.3.0 | 72 / 0 | |
| 3.2.1 | 72 / 0 | |
| 3.2.0 | 72 / 0 | |
| 3.1.3 | 72 / 0 | |
| 3.1.1 | 72 / 0 | |
| 3.1.0 | 72 / 0 | |
| 3.0.1 | 72 / 0 | |
| 1.18.0 | 11 / 0 | |
| 1.17.0 | 11 / 0 | |
| 1.16.1 | 11 / 0 | |
| 1.16.0 | 11 / 0 | |
| 1.15.0 | 11 / 0 | |
| 1.14.0 | 11 / 0 | |
| 1.13.0 | 11 / 0 | |
| 1.12.0 | 11 / 0 |
v3.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.7.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.