@flux-ui/internals
Contains internal workings of Flux UI packages.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/composable-Cr4VA1Rs.js | AI (source-diff): Bundled ESM chunk from tsdown; readable logic, no obfuscation indicators. | ai | |
| source-diff | obfuscated-file:dist/util-vNzwiqjo.js | AI (source-diff): Bundled ESM chunk from tsdown; readable utility code, no obfuscation indicators. | ai | |
| source-diff | obfuscated-file:dist/composable-ByAxh3HA.js | AI (source-diff): Standard minified bundle output from tsdown build; content is readable Vue composable logic, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/util-DjGcg63Z.js | AI (source-diff): Standard minified bundle output from tsdown build; content is readable utility functions, not obfuscated malware. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI/CD pipeline with SLSA provenance; rapid publishes expected when releasing multiple packages in a monorepo. | ai |
Versions (showing 46 of 46)
| Version | Deps | Published |
|---|---|---|
| 3.13.1 | 4 / 3 | |
| 3.13.0 | 4 / 3 | |
| 3.12.1 | 4 / 3 | |
| 3.12.0 | 4 / 3 | |
| 3.11.0 | 4 / 3 | |
| 3.10.4 | 4 / 3 | |
| 3.10.3 | 4 / 3 | |
| 3.10.2 | 4 / 3 | |
| 3.10.1 | 4 / 3 | |
| 3.10.0 | 4 / 3 | |
| 3.9.1 | 4 / 3 | |
| 3.9.0 | 4 / 3 | |
| 3.8.3 | 4 / 3 | |
| 3.8.2 | 4 / 3 | |
| 3.8.1 | 4 / 3 | |
| 3.8.0 | 4 / 3 | |
| 3.7.2 | 4 / 3 | |
| 3.7.1 | 4 / 3 | |
| 3.7.0 | 4 / 3 | |
| 3.6.1 | 4 / 3 | |
| 3.6.0 | 4 / 3 | |
| 3.5.2 | 4 / 3 | |
| 3.5.1 | 4 / 3 | |
| 3.5.0 | 4 / 3 | |
| 3.4.0 | 4 / 3 | |
| 3.3.2 | 4 / 3 | |
| 3.3.1 | 4 / 3 | |
| 3.3.0 | 4 / 3 | |
| 3.2.6 | 4 / 3 | |
| 3.2.5 | 4 / 3 | |
| 3.2.4 | 4 / 3 | |
| 3.2.3 | 4 / 3 | |
| 3.2.2 | 4 / 3 | |
| 3.2.1 | 4 / 3 | |
| 3.2.0 | 4 / 3 | |
| 3.1.12 | 4 / 3 | |
| 3.1.9 | 4 / 3 | |
| 3.1.8 | 4 / 3 | |
| 3.1.7 | 4 / 3 | |
| 3.1.6 | 4 / 3 | |
| 3.1.5 | 4 / 3 | |
| 3.1.4 | 4 / 3 | |
| 3.1.3 | 4 / 3 | |
| 3.1.2 | 4 / 3 | |
| 3.1.0 | 4 / 3 | |
| 3.0.0 | 4 / 3 |
v3.13.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.12.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.10.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.10.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.10.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.9.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.7.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.2.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.2.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.2.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.2.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.