← Home

@gentleduck/primitives

Unstyled, accessibility-first UI primitives for React.

53
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

wildduck

Keywords

ariagentleduckbehavioralcomponentaccessibilitya11yreact-ariaprimitivesuireact

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/slot-CLdrdHf6.js AI (source-diff): Standard tsdown-minified bundle output for a React UI library; not malicious obfuscation. ai
source-diff obfuscated-file:dist/slot-D38kKvkN.js AI (source-diff): Minified build output from tsdown bundler; content is standard React utility code, not obfuscation. ai
source-diff obfuscated-file:dist/sheet-Bw7hCgJT.js AI (source-diff): Standard tsdown/rollup minified bundle output; readable React component logic, no malicious patterns. ai
source-diff obfuscated-file:dist/sheet-CfX8z3ig.js AI (source-diff): Standard minified ESM bundle output from tsdown build tool; content is readable React component code. ai
source-diff obfuscated-file:dist/floating-ui.react-Cc-GJHbx.js AI (source-diff): Minified bundle of @floating-ui/react; standard DOM utility code, no malicious patterns. ai
source-diff obfuscated-file:dist/slider-CPgU6fPw.js AI (source-diff): Minified bundle output; content is clsx + tailwind-merge utilities and a slider component, no malicious patterns. ai
source-diff obfuscated-file:dist/sheet-BHTdzz3B.js AI (source-diff): Minified bundle output; content is React sheet/drawer component using floating-ui, no malicious patterns. ai
source-diff obfuscated-file:dist/dialog.hooks-CNvzV8zU.js AI (source-diff): Minified bundle output; content is React dialog component using floating-ui, no malicious patterns. ai
source-diff obfuscated-file:dist/sheet-DnRRK6-b.js AI (source-diff): Standard tsdown minified ESM bundle; code is readable React/floating-ui component logic, no malicious patterns. ai
source-diff obfuscated-file:dist/dialog.hooks-BXV4OhfI.js AI (source-diff): Standard tsdown minified ESM bundle; code is readable React/floating-ui component logic, no malicious patterns. ai
source-diff obfuscated-file:dist/dialog.hooks-CqFZF_5e.js AI (source-diff): Standard minified bundle; content is React dialog component logic using floating-ui. ai
source-diff obfuscated-file:dist/slider-BkdTG_Wi.js AI (source-diff): Standard minified bundle; content is React slider with tailwind-merge utilities. ai
source-diff obfuscated-file:dist/sheet-D-3jJM42.js AI (source-diff): Standard minified bundle; content is React sheet component using floating-ui. ai
source-diff obfuscated-file:dist/floating-ui.react-CU0wwk7J.js AI (source-diff): Bundled floating-ui library; content matches known floating-ui DOM utilities. ai
source-diff obfuscated-file:dist/checkers-DryVluzz.js AI (source-diff): Standard minified bundle output; content is CSS color regex maps, not malicious code. ai
source-diff obfuscated-file:dist/slider-Bxshtbqw.js AI (source-diff): Minified slider component bundle; content is normal React/tailwind-merge logic. ai
source-diff obfuscated-file:dist/floating-ui.react-_WejR-w5.js AI (source-diff): Minified re-export of @floating-ui/react; content matches expected library code. ai
source-diff obfuscated-file:dist/dialog.hooks--d4UWYhb.js AI (source-diff): Standard tsdown minified ESM bundle output; readable React component logic in sample. ai
provenance missing-githead AI (provenance): Publish workflow change (removed publish script) explains missing gitHead; no other risk signals present. ai
source-diff obfuscated-file:dist/dialog-CGkLSvry.js AI (source-diff): Minified tsdown bundle output; samples show legitimate React/floating-ui component code, no malicious patterns. ai
source-diff obfuscated-file:dist/popover/index.js AI (source-diff): Minified tsdown bundle output; samples show legitimate React/floating-ui component code, no malicious patterns. ai
source-diff obfuscated-file:dist/sheet/index.js AI (source-diff): Minified tsdown bundle output; samples show legitimate React/floating-ui component code, no malicious patterns. ai
source-diff obfuscated-file:dist/sheet-44l4cGdK.js AI (source-diff): Standard bundler minification of React/floating-ui components; no obfuscation or malicious payload. ai
source-diff obfuscated-file:dist/dialog.hooks-e3NZPgTS.js AI (source-diff): Standard bundler minification of React/floating-ui components; no obfuscation or malicious payload. ai
provenance no-provenance AI (provenance): Publisher has clean track record; provenance not enabled but no malicious indicators present. ai
source-diff obfuscated-file:dist/content-CDe_RDmz.js AI (source-diff): Standard Vite/tsdown minified ESM bundle output; content is readable React/floating-ui logic, not obfuscation. ai
source-diff obfuscated-file:dist/content-HKxfa6-O.js AI (source-diff): Standard Vite/tsdown minified ESM bundle; imports known packages, readable menu component logic. ai
source-diff obfuscated-file:dist/popper/content.js AI (source-diff): Standard tsdown minified ESM output; legitimate React component code. ai
source-diff obfuscated-file:dist/popover/content.js AI (source-diff): Standard tsdown minified ESM output; legitimate React component code. ai
source-diff obfuscated-file:dist/navigation-menu/content.js AI (source-diff): Standard tsdown minified ESM output; legitimate React component code. ai
source-diff obfuscated-file:dist/menu/content.js AI (source-diff): Standard tsdown minified ESM output; legitimate React component code. ai
source-diff obfuscated-file:dist/checkers-DDU4mSPA.js AI (source-diff): Standard tsdown minified ESM output; content is readable color-regex library code. ai
source-diff obfuscated-file:dist/hover-card/content.js AI (source-diff): Standard tsdown minified ESM output; legitimate React component code. ai
source-diff source-size-tripled AI (source-diff): Size increase matches addition of multiple new component modules. ai
source-diff large-new-source-files AI (source-diff): Large file count reflects new UI primitive components, not injected code. ai
source-diff obfuscated-file:dist/tooltip/content.js AI (source-diff): Standard tsdown minified ESM output; legitimate React component code. ai
source-diff obfuscated-file:dist/select/content.js AI (source-diff): Standard tsdown minified ESM output; legitimate React component code. ai
source-diff obfuscated-file:dist/content-D-insCJ9.js AI (source-diff): Standard tsdown/Rollup minified ESM bundle; content is readable React/floating-ui code, no malicious patterns. ai
source-diff obfuscated-file:dist/dropdown-menu/content.js AI (source-diff): Standard tsdown/Rollup minified ESM bundle; barrel re-export of menu primitives, no malicious patterns. ai
source-diff obfuscated-file:dist/context-menu/content.js AI (source-diff): Standard tsdown/Rollup minified ESM bundle; barrel re-export of menu primitives, no malicious patterns. ai
source-diff obfuscated-file:dist/content-XReL-c9p.js AI (source-diff): Standard tsdown/Rollup minified ESM bundle; content is readable React menu primitive code, no malicious patterns. ai
phantom-deps phantom-dep:react-remove-scroll AI (phantom-deps): Declared runtime dep; used indirectly via re-exports in this primitives package. ai
phantom-deps phantom-dep:aria-hidden AI (phantom-deps): Declared runtime dep; used indirectly via re-exports in this primitives package. ai

Versions (showing 53 of 53)

Version Deps Published
0.3.0 4 / 15
0.2.14 4 / 15
0.2.13 4 / 15
0.2.12 4 / 15
0.2.11 4 / 15
0.2.10 4 / 15
0.2.9 4 / 15
0.2.8 4 / 15
0.2.7 4 / 15
0.2.6 3 / 11
0.2.5 3 / 11
0.2.4 3 / 11
0.2.3 3 / 11
0.2.1 3 / 11
0.2.0 0 / 11
0.1.45 0 / 12
0.1.44 0 / 12
0.1.43 0 / 12
0.1.42 0 / 12
0.1.41 0 / 13
0.1.39 0 / 13
0.1.38 0 / 13
0.1.36 0 / 13
0.1.35 0 / 12
0.1.34 0 / 8
0.1.33 0 / 8
0.1.32 0 / 8
0.1.31 0 / 8
0.1.30 0 / 8
0.1.29 0 / 8
0.1.28 0 / 8
0.1.25 0 / 8
0.1.24 0 / 8
0.1.23 0 / 6
0.1.20 0 / 6
0.1.19 0 / 6
0.1.18 0 / 6
0.1.17 0 / 6
0.1.16 0 / 6
0.1.15 0 / 5
0.1.14 0 / 5
0.1.13 0 / 5
0.1.12 0 / 5
0.1.11 0 / 5
0.1.10 0 / 3
0.1.9 0 / 3
0.1.8 0 / 3
0.1.7 0 / 3
0.1.6 0 / 3
0.1.5 0 / 3
0.1.2 0 / 3
0.1.1 0 / 3
0.1.0 0 / 3

v0.3.0

2 findings
HIGH New obfuscated file: dist/slot-D38kKvkN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.14

2 findings
HIGH New obfuscated file: dist/slot-CLdrdHf6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.9

9 findings
HIGH New obfuscated file: dist/checkers-DDU4mSPA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/hover-card/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/navigation-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popover/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popper/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/select/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/tooltip/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.8

9 findings
HIGH New obfuscated file: dist/checkers-DDU4mSPA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/hover-card/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/navigation-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popover/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popper/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/select/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/tooltip/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.7

9 findings
HIGH New obfuscated file: dist/checkers-DDU4mSPA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/hover-card/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/navigation-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popover/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popper/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/select/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/tooltip/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.6

9 findings
HIGH New obfuscated file: dist/checkers-DDU4mSPA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/hover-card/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/navigation-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popover/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popper/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/select/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/tooltip/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.5

5 findings
HIGH New obfuscated file: dist/content-CDe_RDmz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/content-HKxfa6-O.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/context-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/dropdown-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.4

5 findings
HIGH New obfuscated file: dist/content-D-insCJ9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/content-XReL-c9p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/context-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/dropdown-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.3

5 findings
HIGH New obfuscated file: dist/content-D-insCJ9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/content-XReL-c9p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/context-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/dropdown-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

5 findings
HIGH New obfuscated file: dist/content-D-insCJ9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/content-XReL-c9p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/context-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/dropdown-menu/content.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

4 findings
HIGH New obfuscated file: dist/dialog.hooks--d4UWYhb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/floating-ui.react-_WejR-w5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/slider-Bxshtbqw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.44

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.38

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.36

7 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

HIGH New obfuscated file: dist/checkers-DryVluzz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/dialog.hooks-CqFZF_5e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/floating-ui.react-CU0wwk7J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sheet-D-3jJM42.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/slider-BkdTG_Wi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.35

7 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

HIGH New obfuscated file: dist/checkers-DryVluzz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/dialog.hooks-CNvzV8zU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/floating-ui.react-Cc-GJHbx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sheet-BHTdzz3B.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/slider-CPgU6fPw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.34

4 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

HIGH New obfuscated file: dist/dialog.hooks-BXV4OhfI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sheet-DnRRK6-b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.33

4 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

HIGH New obfuscated file: dist/dialog.hooks-BXV4OhfI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sheet-DnRRK6-b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.32

4 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

HIGH New obfuscated file: dist/dialog.hooks-e3NZPgTS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sheet-CfX8z3ig.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.31

4 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

HIGH New obfuscated file: dist/dialog.hooks-e3NZPgTS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sheet-Bw7hCgJT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.30

4 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

HIGH New obfuscated file: dist/dialog.hooks-e3NZPgTS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sheet-44l4cGdK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.29

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.28

4 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

HIGH New obfuscated file: dist/dialog.hooks-e3NZPgTS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sheet-44l4cGdK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.25

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

HIGH New obfuscated file: dist/dialog-CGkLSvry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popover/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sheet/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.24

4 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

HIGH New obfuscated file: dist/popover/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sheet/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.23

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.20

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.18

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: wildduck.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.