@everymatrix/helper-date-navigator
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/esm/helper-date-navigator-4f3c3c05.js | AI (source-diff): Standard minified Stencil/Vaadin bundle; long lines are SVG data and bundler output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/cjs/helper-date-navigator-ad70f19b.js | AI (source-diff): CJS variant; same legitimate Vaadin/Stencil component patterns. | ai | |
| source-diff | obfuscated-file:dist/cjs/helper-date-navigator-ad70f19b.js | AI (source-diff): CJS variant of the same minified bundle; not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/helper-date-navigator/helper-date-navigator-4f3c3c05.js | AI (source-diff): Same as ESM variant; legitimate Vaadin component code. | ai | |
| source-diff | obfuscated-file:dist/helper-date-navigator/helper-date-navigator-4f3c3c05.js | AI (source-diff): Same minified Stencil bundle; long lines are expected bundler output for this component. | ai | |
| source-diff | net-exec-file:dist/esm/helper-date-navigator-4f3c3c05.js | AI (source-diff): Network/exec pattern fires on legitimate Vaadin component fetch/Promise patterns in bundled UI code. | ai | |
| source-diff | obfuscated-file:dist/esm/helper-date-navigator-28673bc8.js | AI (source-diff): Same minified Stencil/Vaadin build output pattern; false positive. | ai | |
| source-diff | obfuscated-file:dist/cjs/helper-date-navigator-2637f184.js | AI (source-diff): Standard minified Stencil/Vaadin build output; long lines are SVG path data and bundled component code. | ai | |
| source-diff | net-exec-file:dist/cjs/helper-date-navigator-2637f184.js | AI (source-diff): Network/exec pattern fires on customElements.define and Promise usage in bundled component; no actual dropper behavior. | ai | |
| source-diff | net-exec-file:dist/esm/helper-date-navigator-28673bc8.js | AI (source-diff): Same false positive pattern as CJS counterpart. | ai | |
| source-diff | obfuscated-file:dist/helper-date-navigator/helper-date-navigator-28673bc8.js | AI (source-diff): Minified Stencil bundle; long lines are legitimate bundled component code. | ai | |
| source-diff | net-exec-file:dist/helper-date-navigator/helper-date-navigator-28673bc8.js | AI (source-diff): Same false positive; customElements/Promise usage in a UI component bundle is not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/esm/helper-date-navigator-6fa6fff7.js | AI (source-diff): Same false positive as CJS counterpart. | ai | |
| source-diff | net-exec-file:dist/helper-date-navigator/helper-date-navigator-6fa6fff7.js | AI (source-diff): False positive; customElements and Promise are standard web component APIs. | ai | |
| source-diff | obfuscated-file:dist/helper-date-navigator/helper-date-navigator-6fa6fff7.js | AI (source-diff): Minified ESM bundle; long lines are legitimate bundled component code. | ai | |
| source-diff | obfuscated-file:dist/cjs/helper-date-navigator-212cbc53.js | AI (source-diff): Standard minified Stencil/Vaadin bundle; long lines are SVG path data and bundled component code, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/cjs/helper-date-navigator-212cbc53.js | AI (source-diff): Network/exec pattern matches Vaadin customElements.define and Promise usage in component bundle, not dropper malware. | ai | |
| source-diff | obfuscated-file:dist/esm/helper-date-navigator-6fa6fff7.js | AI (source-diff): Same minified Stencil/Vaadin bundle pattern; false positive. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped enterprise package (@everymatrix) with 126 versions; sparse metadata is typical for internal component libraries. | ai |
Versions (showing 51 of 203)
| Version | Deps | Published |
|---|---|---|
| 0.8.81 | 0 / 0 | |
| 0.8.80 | 0 / 0 | |
| 0.8.79 | 0 / 0 | |
| 0.8.78 | 0 / 0 | |
| 0.8.77 | 0 / 0 | |
| 0.8.76 | 0 / 0 | |
| 0.8.75 | 0 / 0 | |
| 0.8.74 | 0 / 0 | |
| 0.8.73 | 0 / 0 | |
| 0.8.72 | 0 / 0 | |
| 0.8.71 | 0 / 0 | |
| 0.8.70 | 0 / 0 | |
| 0.8.69 | 0 / 0 | |
| 0.8.68 | 0 / 0 | |
| 0.8.67 | 0 / 0 | |
| 0.8.66 | 0 / 0 | |
| 0.8.65 | 0 / 0 | |
| 0.8.64 | 0 / 0 | |
| 0.8.63 | 0 / 0 | |
| 0.8.62 | 0 / 0 | |
| 0.8.61 | 0 / 0 | |
| 0.8.60 | 0 / 0 | |
| 0.8.59 | 0 / 0 | |
| 0.8.58 | 0 / 0 | |
| 0.8.57 | 0 / 0 | |
| 0.8.56 | 0 / 0 | |
| 0.8.55 | 0 / 0 | |
| 0.8.54 | 0 / 0 | |
| 0.8.53 | 0 / 0 | |
| 0.8.52 | 0 / 0 | |
| 0.8.51 | 0 / 0 | |
| 0.8.50 | 0 / 0 | |
| 0.8.49 | 0 / 0 | |
| 0.8.48 | 0 / 0 | |
| 0.8.47 | 0 / 0 | |
| 0.8.46 | 0 / 0 | |
| 0.8.45 | 0 / 0 | |
| 0.8.44 | 0 / 0 | |
| 0.8.43 | 0 / 0 | |
| 0.8.42 | 0 / 0 | |
| 0.8.41 | 0 / 0 | |
| 0.8.40 | 0 / 0 | |
| 0.8.39 | 0 / 0 | |
| 0.8.38 | 0 / 0 | |
| 0.8.37 | 0 / 0 | |
| 0.8.36 | 0 / 0 | |
| 0.8.35 | 0 / 0 | |
| 0.8.34 | 0 / 0 | |
| 0.8.33 | 0 / 0 | |
| 0.8.32 | 0 / 0 | |
| 0.8.31 | 0 / 0 |
v0.8.81
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.80
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.79
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.78
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.77
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.76
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.75
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.74
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.73
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.72
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.71
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.70
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.69
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.68
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.67
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.66
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.65
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.64
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.63
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.62
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.61
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.60
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.59
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.58
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.57
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.56
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.55
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.54
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.53
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.