@elastic/eui
Elastic UI Component Library
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:test-env/components/form/form_control_layout/append_prepend/form_append_prepend.js | AI (source-diff): Test-env Babel output; benign minified dist file. | ai | |
| source-diff | obfuscated-file:lib/components/form/form_control_layout/append_prepend/form_append_prepend.js | AI (source-diff): CJS Babel transpile output; benign minified dist file. | ai | |
| source-diff | obfuscated-file:es/components/form/form_control_layout/append_prepend/form_append_prepend.js | AI (source-diff): Standard Babel build output, not obfuscation; benign for this distributed component library. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Webpack chunk-loader for icon assets; standard lazy-load pattern, not arbitrary module loading. | ai | |
| dependencies | unvetted-dep:remark-parse-no-trim | AI (dependencies): Known remark ecosystem package used for markdown parsing; stable for this package. | ai | |
| dependencies | unvetted-dep:@elastic/eui-theme-common | AI (dependencies): Elastic-owned sibling package in the EUI monorepo; stable for this package. | ai | |
| dependencies | unvetted-dep:@elastic/prismjs-esql | AI (dependencies): Elastic-owned syntax highlighting extension; stable for this package. | ai | |
| dependencies | unvetted-dep:@types/refractor | AI (dependencies): Type-only package for refractor; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:es/components/context_menu/context_menu_panel_title.js | AI (source-diff): Babel-transpiled React component with readable code and Elastic copyright; long-line heuristic false positive on bundled output. | ai | |
| source-diff | obfuscated-file:lib/components/context_menu/context_menu_panel_title.js | AI (source-diff): Same as es/ variant — CJS Babel output, not obfuscated. | ai | |
| source-diff | obfuscated-file:test-env/components/context_menu/context_menu_panel_title.js | AI (source-diff): Same pattern — test-env Babel output, not obfuscated. | ai | |
| phantom-deps | phantom-dep:@types/numeral | AI (phantom-deps): @types/* packages are type-only; phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:@types/lodash | AI (phantom-deps): @types/* packages are type-only and loaded by convention in TS projects; not an injection vector. | ai | |
| phantom-deps | phantom-dep:@types/react-window | AI (phantom-deps): @types/* packages are type-only; phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:@types/refractor | AI (phantom-deps): @types/* packages are type-only; phantom-dep heuristic is a stable false positive here. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped @elastic package; levenshtein match against 'uuid' is a false positive. | ai | |
| phantom-deps | phantom-dep:react-element-to-jsx-string | AI (phantom-deps): Used in code display/playground components; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:rehype-raw | AI (phantom-deps): Established Elastic UI library; rehype-raw is a legitimate markdown/HTML processing dep used in component internals. | ai | |
| phantom-deps | phantom-dep:rehype-stringify | AI (phantom-deps): Legitimate rehype pipeline dep in a large component library; analyzer likely misses indirect import paths. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @elastic package; levenshtein match against 'yup' is a false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @elastic package; levenshtein match against 'joi' is a false positive. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 117.1.0 | 36 / 137 | |
| 117.0.0 | 36 / 155 | |
| 116.5.0 | 36 / 155 | |
| 116.4.0 | 36 / 155 | |
| 116.3.1 | 36 / 154 | |
| 116.3.0 | 36 / 154 | |
| 116.2.0 | 36 / 154 | |
| 116.1.0 | 36 / 155 | |
| 116.0.0 | 36 / 155 | |
| 115.0.0 | 36 / 155 | |
| 114.3.0 | 36 / 163 | |
| 114.2.0 | 36 / 163 | |
| 114.1.0 | 36 / 163 | |
| 114.0.0 | 36 / 162 | |
| 113.3.0 | 36 / 162 | |
| 113.2.1 | 36 / 162 | |
| 113.2.0 | 36 / 162 | |
| 113.1.0 | 36 / 162 | |
| 113.0.0 | 36 / 164 | |
| 112.3.0 | 36 / 164 | |
| 112.2.0 | 36 / 164 | |
| 112.1.0 | 36 / 164 | |
| 112.0.0 | 36 / 164 | |
| 111.1.0 | 36 / 164 | |
| 111.0.0 | 36 / 164 | |
| 110.0.0 | 35 / 164 | |
| 109.2.0 | 35 / 164 | |
| 109.1.0 | 35 / 164 | |
| 109.0.0 | 35 / 164 |
v117.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v117.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v116.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v116.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v114.0.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v113.3.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v113.2.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v113.2.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v113.1.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v113.0.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v112.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v112.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v112.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v112.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v111.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v111.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v110.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v109.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v109.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v109.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.