@everymatrix/general-navigation-bar
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/GeneralNavigationBar-Bfh7WG4E.js | AI (source-diff): Standard ESM build output of Svelte component; stable for this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-Qb1CAewK.cjs | AI (source-diff): Standard minified CJS build output of Svelte component; stable for this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-BlSfGwXK.js | AI (source-diff): Standard minified ESM build output of Svelte component; stable for this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-Ci53k2cM.js | AI (source-diff): Standard Vite/Rollup minified build output with hashed filename; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/SvgImage-CQdagKOq.js | AI (source-diff): Minified build artifact importing from sibling bundle; contains DOMPurify with license comment. | ai | |
| source-diff | obfuscated-file:components/SvgImage-6AwvqW0h.js | AI (source-diff): Minified build artifact importing from sibling bundle; contains DOMPurify with license comment. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-5O3Ok2u7.js | AI (source-diff): Standard Vite/Rollup minified build output with hashed filename; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-yLFjX6uX.cjs | AI (source-diff): Standard Svelte/Vite minified CJS build output; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-BhV-ZEQ_.js | AI (source-diff): Standard Svelte/Vite minified ESM build output; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-BVnUQn3k.js | AI (source-diff): Standard Svelte/Vite minified ESM build output; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-KA3XrTn-.js | AI (source-diff): Standard Vite/Svelte minified build output; consistent pattern across all versions of this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-3tHXiBpJ.cjs | AI (source-diff): Standard Vite/Svelte minified build output; consistent pattern across all versions of this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-D50sJjtZ.js | AI (source-diff): Standard Vite/Svelte minified build output; consistent pattern across all versions of this package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-Cs0rLyzI.js | AI (source-diff): Standard Vite/Rollup minified bundle output; hashed filenames are expected for this package's build pipeline. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable characteristic of this scoped org package across all versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped org package with 520 versions; missing metadata is a stable characteristic, not a spam indicator. | ai | |
| source-diff | obfuscated-file:components/SvgImage-DrAEJwuH.js | AI (source-diff): Standard Vite/Rollup minified bundle output; hashed filenames are expected for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:components/SvgImage-BaZ9-UX2.js | AI (source-diff): Standard Vite/Rollup minified bundle output; hashed filenames are expected for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-D8QKT7ul.js | AI (source-diff): Standard Vite/Rollup minified bundle output; hashed filenames are expected for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-CO8EAnTc.js | AI (source-diff): Standard minified Svelte ESM build artifact; consistent pattern across all versions of this UI component package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-lq5uM3PL.js | AI (source-diff): Standard minified Svelte ESM build artifact; consistent pattern across all versions of this UI component package. | ai | |
| source-diff | obfuscated-file:components/GeneralNavigationBar-CT5LjIyp.cjs | AI (source-diff): Standard minified Svelte CJS build artifact; consistent pattern across all versions of this UI component package. | ai |
Versions (showing 5 of 147)
| Version | Deps | Published |
|---|---|---|
| 1.67.0 | 0 / 0 | |
| 1.66.2 | 0 / 0 | |
| 1.66.1 | 0 / 0 | |
| 1.66.0 | 0 / 0 | |
| 1.65.3 | 0 / 0 |
v1.67.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.