@everymatrix/general-navigation-bar
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/GeneralNavigationBar-C-cp1KVV.js | AI (source-diff): Bundled Svelte build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/SvgImage-C27690jh.js | AI (source-diff): Bundled DOMPurify/build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/SvgImage-BjWTcgoS.js | AI (source-diff): Bundled DOMPurify/build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/SvgImage-B6pcbBo6.cjs | AI (source-diff): Bundled DOMPurify/build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-Cp-g7VYB.cjs | AI (source-diff): Bundled Svelte build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-CI2pPGZn.js | AI (source-diff): Bundled Svelte build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-CGs3gpFJ.js | AI (source-diff): Standard minified Svelte component bundle output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-DNxhH4WA.js | AI (source-diff): Standard minified Svelte component bundle output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-BHbOqmH4.cjs | AI (source-diff): Standard minified Svelte component bundle output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-Bfh7WG4E.js | AI (source-diff): Standard ESM build output of Svelte component; stable for this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-BlSfGwXK.js | AI (source-diff): Standard minified ESM build output of Svelte component; stable for this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-Qb1CAewK.cjs | AI (source-diff): Standard minified CJS build output of Svelte component; stable for this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-5O3Ok2u7.js | AI (source-diff): Standard Vite/Rollup minified build output with hashed filename; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-Ci53k2cM.js | AI (source-diff): Standard Vite/Rollup minified build output with hashed filename; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/SvgImage-6AwvqW0h.js | AI (source-diff): Minified build artifact importing from sibling bundle; contains DOMPurify with license comment. | ai | |
| source-diff | obfuscated-file:components/SvgImage-CQdagKOq.js | AI (source-diff): Minified build artifact importing from sibling bundle; contains DOMPurify with license comment. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-BVnUQn3k.js | AI (source-diff): Standard Svelte/Vite minified ESM build output; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-BhV-ZEQ_.js | AI (source-diff): Standard Svelte/Vite minified ESM build output; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-yLFjX6uX.cjs | AI (source-diff): Standard Svelte/Vite minified CJS build output; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-3tHXiBpJ.cjs | AI (source-diff): Standard Vite/Svelte minified build output; consistent pattern across all versions of this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-KA3XrTn-.js | AI (source-diff): Standard Vite/Svelte minified build output; consistent pattern across all versions of this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-D50sJjtZ.js | AI (source-diff): Standard Vite/Svelte minified build output; consistent pattern across all versions of this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-Cs0rLyzI.js | AI (source-diff): Standard Vite/Rollup minified bundle output; hashed filenames are expected for this package's build pipeline. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable characteristic of this scoped org package across all versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped org package with 520 versions; missing metadata is a stable characteristic, not a spam indicator. | ai | |
| source-diff | obfuscated-file:components/SvgImage-DrAEJwuH.js | AI (source-diff): Standard Vite/Rollup minified bundle output; hashed filenames are expected for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:components/SvgImage-BaZ9-UX2.js | AI (source-diff): Standard Vite/Rollup minified bundle output; hashed filenames are expected for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-D8QKT7ul.js | AI (source-diff): Standard Vite/Rollup minified bundle output; hashed filenames are expected for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-CO8EAnTc.js | AI (source-diff): Standard minified Svelte ESM build artifact; consistent pattern across all versions of this UI component package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-lq5uM3PL.js | AI (source-diff): Standard minified Svelte ESM build artifact; consistent pattern across all versions of this UI component package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-CT5LjIyp.cjs | AI (source-diff): Standard minified Svelte CJS build artifact; consistent pattern across all versions of this UI component package. | ai |
Versions (showing 51 of 281)
| Version | Deps | Published |
|---|---|---|
| 1.94.81 | 0 / 0 | |
| 1.94.59 | 0 / 0 | |
| 1.94.58 | 0 / 0 | |
| 1.94.57 | 0 / 0 | |
| 1.94.56 | 0 / 0 | |
| 1.94.55 | 0 / 0 | |
| 1.94.54 | 0 / 0 | |
| 1.94.53 | 0 / 0 | |
| 1.94.52 | 0 / 0 | |
| 1.94.51 | 0 / 0 | |
| 1.94.50 | 0 / 0 | |
| 1.94.49 | 0 / 0 | |
| 1.94.48 | 0 / 0 | |
| 1.94.47 | 0 / 0 | |
| 1.94.46 | 0 / 0 | |
| 1.94.45 | 0 / 0 | |
| 1.94.44 | 0 / 0 | |
| 1.94.43 | 0 / 0 | |
| 1.94.42 | 0 / 0 | |
| 1.94.41 | 0 / 0 | |
| 1.94.40 | 0 / 0 | |
| 1.94.39 | 0 / 0 | |
| 1.94.38 | 0 / 0 | |
| 1.94.37 | 0 / 0 | |
| 1.94.36 | 0 / 0 | |
| 1.94.35 | 0 / 0 | |
| 1.94.34 | 0 / 0 | |
| 1.94.33 | 0 / 0 | |
| 1.94.32 | 0 / 0 | |
| 1.94.31 | 0 / 0 | |
| 1.94.30 | 0 / 0 | |
| 1.94.29 | 0 / 0 | |
| 1.94.28 | 0 / 0 | |
| 1.94.27 | 0 / 0 | |
| 1.94.26 | 0 / 0 | |
| 1.94.25 | 0 / 0 | |
| 1.94.24 | 0 / 0 | |
| 1.94.23 | 0 / 0 | |
| 1.94.22 | 0 / 0 | |
| 1.94.21 | 0 / 0 | |
| 1.94.20 | 0 / 0 | |
| 1.94.19 | 0 / 0 | |
| 1.94.18 | 0 / 0 | |
| 1.94.17 | 0 / 0 | |
| 1.94.16 | 0 / 0 | |
| 1.94.15 | 0 / 0 | |
| 1.94.9 | 0 / 0 | |
| 1.94.8 | 0 / 0 | |
| 1.94.7 | 0 / 0 | |
| 1.94.6 | 0 / 0 | |
| 1.94.5 | 0 / 0 |
v1.94.81
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.59
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.58
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.57
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.56
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.55
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.54
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.53
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.