@dynatrace/strato-components-preview
::: A simpler way to use Strato
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:migrations/3.0.0/codemods/remove-deprecated-timeframe-selector-from-forms.js | AI (source-diff): heuristic fired on bundled lodash _.template Function() + license URLs; no network sink | ai | |
| source-diff | obfuscated-file:migrations/3.0.0/codemods/remove-deprecated-timeframe-selector-from-forms.js | AI (source-diff): esbuild-bundled jscodeshift codemod; minifier output not obfuscation | ai | |
| source-diff | obfuscated-file:migrations/2.16.0/codeshift-migration.js | AI (source-diff): Bundled jscodeshift codemod tooling, not true obfuscation. | ai | |
| source-diff | net-exec-file:migrations/2.16.0/codeshift-migration.js | AI (source-diff): Bundled codemod tool false-positives on net+exec pattern match. | ai | |
| source-diff | net-exec-file:migrations/2.17.0/codeshift-migration.js | AI (source-diff): Codemod tooling bundle; no concrete exfil/dropper behavior found. | ai | |
| source-diff | obfuscated-file:migrations/2.17.0/codeshift-migration.js | AI (source-diff): Bundled jscodeshift migration script, not obfuscation-with-malicious-behavior. | ai | |
| source-diff | obfuscated-file:migrations/2.14.0/codeshift-migration.js | AI (source-diff): Bundled esbuild codemod script, not true obfuscation; trusted publisher pattern for migration tooling. | ai | |
| source-diff | net-exec-file:migrations/2.14.0/codeshift-migration.js | AI (source-diff): Codemod bundler output; no concrete malicious network/exec behavior found in sample. | ai | |
| source-diff | obfuscated-file:migrations/2.8.0/codeshift-migration.js | AI (source-diff): Bundled codemod tooling (esbuild output), not obfuscation with malicious behavior. | ai | |
| source-diff | net-exec-file:migrations/2.8.0/codeshift-migration.js | AI (source-diff): Migration script legitimately reads/writes local files as part of jscodeshift; no exfil destination. | ai | |
| phantom-deps | phantom-dep:@formatjs/icu-messageformat-parser | AI (phantom-deps): i18n parser used indirectly via react-intl; stable false positive for this component library. | ai | |
| phantom-deps | phantom-dep:type-fest | AI (phantom-deps): Type-only utility; phantom-dep false positive for a component library shipping TypeScript types. | ai | |
| phantom-deps | phantom-dep:@visx/brush | AI (phantom-deps): Visualization sub-package; may be re-exported or used indirectly via peer imports in chart components. | ai | |
| phantom-deps | phantom-dep:@visx/event | AI (phantom-deps): Visualization sub-package; same rationale as @visx/brush. | ai | |
| phantom-deps | phantom-dep:d3-interpolate | AI (phantom-deps): D3 sub-package used transitively by chart utilities; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/modifiers | AI (phantom-deps): DnD sub-package; likely re-exported or used indirectly in sortable components. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/utilities | AI (phantom-deps): DnD sub-package; same rationale as @dnd-kit/modifiers. | ai | |
| phantom-deps | phantom-dep:identity-obj-proxy | AI (phantom-deps): Testing utility; referenced in config files, not a runtime import — stable false positive. | ai | |
| phantom-deps | phantom-dep:@vanilla-extract/css | AI (phantom-deps): CSS-in-JS build-time dep; may not appear as a direct import in compiled output. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Trusted Dynatrace org publisher with clean track record; dormancy likely reflects release cadence, not takeover. | ai | |
| provenance | no-provenance | AI (provenance): Established Dynatrace org package; lack of provenance is consistent across all 106 versions and is not a risk signal here. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 3.4.1 | 1 / 0 | |
| 3.4.0 | 1 / 0 | |
| 3.3.3 | 1 / 0 | |
| 3.3.2 | 1 / 0 | |
| 3.3.1 | 1 / 0 | |
| 3.3.0 | 1 / 0 | |
| 3.2.2 | 1 / 0 | |
| 3.2.1 | 1 / 0 | |
| 3.2.0 | 1 / 0 | |
| 3.1.5 | 1 / 0 | |
| 3.1.3 | 1 / 0 | |
| 3.1.0 | 1 / 0 | |
| 3.0.3 | 1 / 0 | |
| 3.0.1 | 1 / 0 | |
| 2.17.4 | 71 / 0 | |
| 2.17.3 | 71 / 0 | |
| 2.17.2 | 71 / 0 | |
| 2.17.1 | 71 / 0 | |
| 2.17.0 | 71 / 0 | |
| 2.16.0 | 70 / 0 | |
| 2.15.1 | 69 / 0 | |
| 2.13.2 | 70 / 0 | |
| 2.11.2 | 70 / 0 | |
| 2.10.2 | 70 / 0 | |
| 2.9.4 | 69 / 0 | |
| 2.8.3 | 69 / 0 | |
| 2.8.2 | 69 / 0 | |
| 2.8.1 | 69 / 0 | |
| 2.7.5 | 69 / 0 | |
| 2.6.2 | 69 / 0 |
v3.1.0
32 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1
32 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.7.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.