← Home

@elastic/eui

Elastic UI Component Library

29
Versions
SEE LICENSE IN LICENSE.txt
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

gtbackelastic-npm-adminikakavas

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:test-env/components/form/form_control_layout/append_prepend/form_append_prepend.js AI (source-diff): Test-env Babel output; benign minified dist file. ai
source-diff obfuscated-file:lib/components/form/form_control_layout/append_prepend/form_append_prepend.js AI (source-diff): CJS Babel transpile output; benign minified dist file. ai
source-diff obfuscated-file:es/components/form/form_control_layout/append_prepend/form_append_prepend.js AI (source-diff): Standard Babel build output, not obfuscation; benign for this distributed component library. ai
semgrep semgrep:dynamic-require AI (semgrep): Webpack chunk-loader for icon assets; standard lazy-load pattern, not arbitrary module loading. ai
dependencies unvetted-dep:remark-parse-no-trim AI (dependencies): Known remark ecosystem package used for markdown parsing; stable for this package. ai
dependencies unvetted-dep:@elastic/eui-theme-common AI (dependencies): Elastic-owned sibling package in the EUI monorepo; stable for this package. ai
dependencies unvetted-dep:@elastic/prismjs-esql AI (dependencies): Elastic-owned syntax highlighting extension; stable for this package. ai
dependencies unvetted-dep:@types/refractor AI (dependencies): Type-only package for refractor; stable false positive for this package. ai
source-diff obfuscated-file:es/components/context_menu/context_menu_panel_title.js AI (source-diff): Babel-transpiled React component with readable code and Elastic copyright; long-line heuristic false positive on bundled output. ai
source-diff obfuscated-file:lib/components/context_menu/context_menu_panel_title.js AI (source-diff): Same as es/ variant — CJS Babel output, not obfuscated. ai
source-diff obfuscated-file:test-env/components/context_menu/context_menu_panel_title.js AI (source-diff): Same pattern — test-env Babel output, not obfuscated. ai
phantom-deps phantom-dep:@types/numeral AI (phantom-deps): @types/* packages are type-only; phantom-dep heuristic is a stable false positive here. ai
phantom-deps phantom-dep:@types/lodash AI (phantom-deps): @types/* packages are type-only and loaded by convention in TS projects; not an injection vector. ai
phantom-deps phantom-dep:@types/react-window AI (phantom-deps): @types/* packages are type-only; phantom-dep heuristic is a stable false positive here. ai
phantom-deps phantom-dep:@types/refractor AI (phantom-deps): @types/* packages are type-only; phantom-dep heuristic is a stable false positive here. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): Scoped @elastic package; levenshtein match against 'uuid' is a false positive. ai
phantom-deps phantom-dep:react-element-to-jsx-string AI (phantom-deps): Used in code display/playground components; stable false positive for this package. ai
phantom-deps phantom-dep:rehype-raw AI (phantom-deps): Established Elastic UI library; rehype-raw is a legitimate markdown/HTML processing dep used in component internals. ai
phantom-deps phantom-dep:rehype-stringify AI (phantom-deps): Legitimate rehype pipeline dep in a large component library; analyzer likely misses indirect import paths. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped @elastic package; levenshtein match against 'yup' is a false positive. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @elastic package; levenshtein match against 'joi' is a false positive. ai

Versions (showing 29 of 29)

Version Deps Published
117.1.0 36 / 137
117.0.0 36 / 155
116.5.0 36 / 155
116.4.0 36 / 155
116.3.1 36 / 154
116.3.0 36 / 154
116.2.0 36 / 154
116.1.0 36 / 155
116.0.0 36 / 155
115.0.0 36 / 155
114.3.0 36 / 163
114.2.0 36 / 163
114.1.0 36 / 163
114.0.0 36 / 162
113.3.0 36 / 162
113.2.1 36 / 162
113.2.0 36 / 162
113.1.0 36 / 162
113.0.0 36 / 164
112.3.0 36 / 164
112.2.0 36 / 164
112.1.0 36 / 164
112.0.0 36 / 164
111.1.0 36 / 164
111.0.0 36 / 164
110.0.0 35 / 164
109.2.0 35 / 164
109.1.0 35 / 164
109.0.0 35 / 164

v117.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v117.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v116.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v116.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v114.0.0

4 findings
HIGH New obfuscated file: es/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: test-env/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v113.3.0

4 findings
HIGH New obfuscated file: es/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: test-env/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v113.2.1

4 findings
HIGH New obfuscated file: es/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: test-env/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v113.2.0

4 findings
HIGH New obfuscated file: es/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: test-env/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v113.1.0

4 findings
HIGH New obfuscated file: es/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: test-env/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v113.0.0

4 findings
HIGH New obfuscated file: es/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: test-env/components/form/form_control_layout/append_prepend/form_append_prepend.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v112.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v112.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v112.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v112.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v111.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v111.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v110.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v109.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v109.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v109.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.