@elliemae/pui-app-sdk
ICE MT UI Platform Application SDK
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:demo/226.d5b77864.iframe.bundle.js | AI (source-diff): Storybook iframe bundle; network+eval pattern from bundled UI libs, not exfil. | ai | |
| source-diff | net-exec-file:demo/1080.92f6b67a.iframe.bundle.js | AI (source-diff): Bundled demo code, no fetched binary or exfil target found. | ai | |
| source-diff | obfuscated-file:demo/1080.92f6b67a.iframe.bundle.js | AI (source-diff): Storybook demo webpack bundle output, not real obfuscation. | ai | |
| source-diff | obfuscated-file:build/docs/assets/js/04ee7372.d0e9ea9d.js | AI (source-diff): Webpack-bundled Docusaurus docs chunk, no malicious behavior. | ai | |
| source-diff | net-exec-file:demo/329.ff184681bc6fb3182626.manager.bundle.js | AI (source-diff): Webpack manager bundle chunk-loader; standard bundler pattern, not a dropper. | ai | |
| source-diff | obfuscated-file:build/docs/assets/js/04ee7372.c521c7aa.js | AI (source-diff): Docusaurus/webpack bundled docs asset, not true obfuscation. | ai | |
| source-diff | net-exec-file:demo/152.1b006a6c9dff83f29e61.manager.bundle.js | AI (source-diff): Storybook/webpack manager bundle, no malicious network target evident. | ai | |
| source-diff | obfuscated-file:build/docs/assets/js/04ee7372.a9b3e0ad.js | AI (source-diff): Docusaurus webpack bundle, minified not obfuscated. | ai | |
| source-diff | net-exec-file:demo/177.787d9441.iframe.bundle.js | AI (source-diff): Storybook iframe bundle boilerplate, not a dropper. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Webpack chunk-loader boilerplate, dual-use pattern. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal SDK docs live outside README; not a spam package. | ai | |
| source-diff | obfuscated-file:demo/177.3c5bbe97.iframe.bundle.js | AI (source-diff): Webpack-bundled Storybook/docs demo output, not obfuscation. | ai | |
| source-diff | net-exec-file:demo/177.3c5bbe97.iframe.bundle.js | AI (source-diff): Bundled vendor code (React/babel helpers), no dropper behavior. | ai | |
| source-diff | net-exec-file:demo/177.a6f93dd4.iframe.bundle.js | AI (source-diff): Storybook iframe bundle; webpack banner, no dropper behavior. | ai | |
| source-diff | obfuscated-file:demo/1221.9db93c68.iframe.bundle.js | AI (source-diff): Storybook demo bundle; webpack banner + known deps, minified not obfuscated. | ai | |
| source-diff | net-exec-file:demo/1816.1b050d17.iframe.bundle.js | AI (source-diff): Bundled Storybook runtime, not a fetched/executed payload. | ai | |
| source-diff | obfuscated-file:demo/1805.fc0108b2.iframe.bundle.js | AI (source-diff): Storybook demo webpack bundle, minified not obfuscated. | ai | |
| source-diff | net-exec-file:demo/226.3e61f71f6be5e03e3a01.manager.bundle.js | AI (source-diff): Storybook manager bundle; network+eval pattern is bundler runtime, not dropper. | ai | |
| provenance | missing-githead | AI (provenance): Provenance direction unchanged vs prior approved; consistent with long-running internal CI publishing pattern. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval fires inside minified Storybook vendor bundle, not package source. | ai | |
| source-diff | net-exec-file:demo/177.57531a5d.iframe.bundle.js | AI (source-diff): Storybook iframe bundle; network+eval patterns are bundler/runtime artifacts. | ai | |
| source-diff | obfuscated-file:build/docs/assets/js/04ee7372.01dca5e5.js | AI (source-diff): Webpack-bundled Docusaurus docs chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:demo/2065.9b113936.iframe.bundle.js | AI (source-diff): Storybook demo webpack bundle, minified not obfuscated. | ai | |
| source-diff | net-exec-file:demo/2065.9b113936.iframe.bundle.js | AI (source-diff): Storybook manager/iframe bundle; network+eval pattern from bundled telemetry/runtime, not a dropper. | ai | |
| source-diff | net-exec-file:demo/226.c9375b7c30021f046c17.manager.bundle.js | AI (source-diff): Storybook manager legitimately fetches and executes addon code; not malware. | ai | |
| source-diff | source-size-tripled | AI (source-diff): 34x size increase is entirely from bundled demo/docs assets, not runtime code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New Storybook+Docusaurus demo/docs build output accounts for all 364 new files. | ai | |
| source-diff | net-exec-file:demo/docs/226.c9375b7c30021f046c17.manager.bundle.js | AI (source-diff): Same Storybook manager bundle in docs mirror; same rationale. | ai | |
| source-diff | obfuscated-file:demo/226.c9375b7c30021f046c17.manager.bundle.js | AI (source-diff): Storybook manager bundle; minified webpack output is expected for this demo artifact. | ai |
Versions (showing 26 of 126)
| Version | Deps | Published |
|---|---|---|
| 5.5.1 | 0 / 27 | |
| 5.5.0 | 0 / 27 | |
| 5.4.1 | 0 / 27 | |
| 5.4.0 | 0 / 27 | |
| 5.3.10 | 0 / 27 | |
| 5.3.9 | 0 / 27 | |
| 5.3.8 | 0 / 27 | |
| 5.3.7 | 0 / 27 | |
| 5.3.6 | 0 / 27 | |
| 5.3.5 | 0 / 27 | |
| 5.3.4 | 0 / 27 | |
| 5.3.3 | 0 / 27 | |
| 5.3.2 | 0 / 26 | |
| 5.3.1 | 0 / 26 | |
| 5.3.0 | 0 / 26 | |
| 5.2.6 | 0 / 26 | |
| 5.2.5 | 0 / 26 | |
| 5.2.4 | 0 / 26 | |
| 5.2.3 | 0 / 26 | |
| 5.2.2 | 0 / 26 | |
| 5.2.1 | 0 / 26 | |
| 5.2.0 | 0 / 26 | |
| 5.1.1 | 0 / 26 | |
| 5.1.0 | 0 / 26 | |
| 5.0.1 | 0 / 26 | |
| 5.0.0 | 0 / 26 |
v5.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.2.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.2.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.2.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.2.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.2.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.2.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.