@e-llm-studio/requirement-ai
---
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/icons/BigEnoughIcon.js | AI (source-diff): Minified bundled SVG icon component, not obfuscation; no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/icons/BigEnoughIcon.js | AI (source-diff): Minified bundled SVG icon component, not obfuscation; no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/components/cra/PartialRequirementContent.module.css.js | AI (source-diff): CSS-module bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/components/cra/PartialRequirementContent.js | AI (source-diff): Minified bundled build output, part of documented export path, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/components/cra/PartialRequirementContent.module.css.js | AI (source-diff): CSS-module bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/components/cra/PartialRequirementContent.js | AI (source-diff): Minified ESM bundle output, matches CJS twin, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/components/UserStoryCard/AttachedContext.js | AI (source-diff): Minified bundler output of a React component, not obfuscation; source available in parallel ESM file. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/components/GapRiskSidebar/GapRiskSidebar.js | AI (source-diff): Bundled React component output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/components/GapRiskSidebar/GapRiskSidebar.module.css.js | AI (source-diff): CSS-module injection helper, standard bundler output. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/components/GapRiskSidebar/GapRiskSidebar.module.css.js | AI (source-diff): CSS-module injection helper, standard bundler output. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/components/GapRiskSidebar/components/GapItem/GapItem.module.css.js | AI (source-diff): CSS-module injection helper, standard bundler output. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/components/GapRiskSidebar/components/GapItem/GapItem.module.css.js | AI (source-diff): CSS-module injection helper, standard bundler output. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/components/GapRiskSidebar/GapRiskSidebar.js | AI (source-diff): Bundled React component output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/components/GapRiskSidebar/components/GapItem/GapItem.js | AI (source-diff): Bundled/minified build output, not obfuscation; no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/components/GapRiskSidebar/components/GapItem/GapItem.js | AI (source-diff): Bundled/minified build output, not obfuscation; no malicious behavior. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Consistent with active org-owned package, no other compromise indicators. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Normal growth of a large component library, not injected code. | ai | |
| provenance | no-provenance | AI (provenance): Published without Sigstore; common, no regression. Not a signal for this first-party library. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): Used via config/build tooling, common false positive pattern for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): date-fns is a well-known, widely-used utility lib; no supply-chain concern. | ai | |
| dependencies | unvetted-dep:pdf-collaborative-tool | AI (dependencies): Also flagged as phantom dep — not directly imported; low actual exposure for this package. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/components/RichTextEditor/Editor/plugins/HighlightNode.js | AI (source-diff): Minified Lexical editor node; standard build output. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/icons/CDIcon.js | AI (source-diff): Minified React/TSlib build output; no true obfuscation indicators. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/icons/CDIcon.js | AI (source-diff): Minified React/TSlib build output; no true obfuscation indicators. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/components/UserStoryCard/ClinicalTrialSection.js | AI (source-diff): Minified React component build output; no true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/components/UserStoryCard/ClinicalTrialSection.js | AI (source-diff): Minified React component build output; no true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/components/UserStoryCard/ClinicalTrialSection.module.css.js | AI (source-diff): CSS module injector pattern; minified but not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/components/UserStoryCard/ClinicalTrialSection.module.css.js | AI (source-diff): CSS module injector pattern; minified but not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/components/RichTextEditor/Editor/plugins/HighlightNode.js | AI (source-diff): Minified Lexical editor node; standard build output. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/icons/Illustration.svg.js | AI (source-diff): Inline SVG as minified JS; standard build output. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/icons/Illustration.svg.js | AI (source-diff): Inline SVG as minified JS; standard build output. | ai | |
| source-diff | obfuscated-file:dist/features/RequirementAI/components/userstory-with-citation/components/InlineUpdatedComponent.js | AI (source-diff): Standard minified build output for a React UI component library; no malicious patterns present. | ai | |
| source-diff | obfuscated-file:dist/cjs/features/RequirementAI/components/userstory-with-citation/components/InlineUpdatedComponent.js | AI (source-diff): Standard minified CJS build output; readable React component logic with no malicious patterns. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-icons | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Same pattern — config-referenced peer dep in a UI component library. | ai | |
| phantom-deps | phantom-dep:react-virtualized-auto-sizer | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:pdf-collaborative-tool | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:remark-breaks | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:monaco-editor | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-window | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-syntax-highlighter | AI (phantom-deps): react-syntax-highlighter is a declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:radix-ui | AI (phantom-deps): radix-ui is a declared runtime dep used via config; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 0.0.225 | 27 / 48 | |
| 0.0.220 | 26 / 48 | |
| 0.0.215 | 26 / 48 | |
| 0.0.185 | 26 / 48 | |
| 0.0.179 | 26 / 48 | |
| 0.0.154 | 26 / 48 | |
| 0.0.150 | 26 / 48 | |
| 0.0.145 | 26 / 48 | |
| 0.0.142 | 26 / 48 | |
| 0.0.137 | 26 / 48 | |
| 0.0.133 | 26 / 48 | |
| 0.0.130 | 26 / 48 | |
| 0.0.129 | 26 / 48 | |
| 0.0.127 | 26 / 48 | |
| 0.0.117 | 24 / 47 | |
| 0.0.112 | 24 / 47 | |
| 0.0.111 | 24 / 47 | |
| 0.0.105 | 24 / 47 | |
| 0.0.104 | 24 / 47 | |
| 0.0.103 | 24 / 47 | |
| 0.0.99 | 17 / 46 | |
| 0.0.98 | 24 / 46 | |
| 0.0.73 | 24 / 47 | |
| 0.0.72 | 24 / 47 | |
| 0.0.55 | 23 / 47 | |
| 0.0.54 | 23 / 47 | |
| 0.0.39 | 22 / 46 | |
| 0.0.18 | 22 / 46 | |
| 0.0.16 | 22 / 46 | |
| 0.0.15 | 22 / 46 | |
| 0.0.9 | 21 / 46 | |
| 0.0.4 | 19 / 45 |
v0.0.225
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (saptyadeep) than the most recent previously approved version (priyanshu-g13) on 2026-07-07, but saptyadeep is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.0.220
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (priyanshu-g13) than the most recent previously approved version (saptyadeep) on 2026-07-03, but priyanshu-g13 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.0.215
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.142
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.133
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.112
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.111
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.99
6 findingsThis version was published by a different npm account than previous versions on 2026-04-30. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.98
6 findingsThis version was published by a different npm account than previous versions on 2026-04-29. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.72
11 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.55
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.54
11 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.