← Home

@ghentcdh/ui

--- Ui ---

36
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

flamsensjoren_gcdh

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:ControlWrapper-Ckzwap0M.js AI (source-diff): Minified Vue bundle output, not true obfuscation; no malicious behavior present. ai
source-diff obfuscated-file:ControlWrapper-DejmeYzV.js AI (source-diff): Minified Vue bundle output, not true obfuscation; consistent with UI library build. ai
source-diff obfuscated-file:index-NGeplssl.js AI (source-diff): Bundled/minified Vue component library output, not true obfuscation; no malicious behavior. ai
source-diff obfuscated-file:ControlWrapper-CilCgWUv.js AI (source-diff): Bundled/minified Vue build output, not obfuscation; no malicious behavior present. ai
source-diff obfuscated-file:testing.js AI (source-diff): testing.js is a minified Playwright page-object bundle, explicitly exported under ./testing; not obfuscated malware. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped org package @ghentcdh/ui; not a typosquat of qs. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped org package @ghentcdh/ui; not a typosquat of pg. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): Scoped org package @ghentcdh/ui; not a typosquat of uuid. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped org package @ghentcdh/ui; not a typosquat of yup. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped org package @ghentcdh/ui; not a typosquat of joi. ai

Versions (showing 36 of 36)

Version Deps Published
3.0.5 0 / 9
3.0.4 0 / 9
3.0.3 0 / 9
3.0.2 0 / 9
3.0.1 0 / 9
3.0.0 0 / 9
2.0.0 0 / 9
1.1.1 6 / 5
1.1.0 0 / 11
1.0.5 0 / 11
1.0.4 0 / 11
1.0.3 0 / 11
1.0.2 0 / 11
1.0.1 0 / 11
0.8.6 0 / 11
0.8.5 0 / 11
0.8.3 0 / 11
0.8.2 0 / 11
0.8.1 0 / 11
0.7.0 0 / 11
0.6.9 0 / 11
0.6.8 0 / 11
0.6.7 0 / 11
0.6.6 0 / 11
0.6.5 0 / 11
0.6.1 0 / 0
0.6.0 0 / 0
0.5.1 0 / 0
0.5.0 0 / 0
0.4.0 0 / 0
0.3.0 0 / 0
0.2.2 0 / 0
0.2.1 0 / 0
0.2.0 0 / 0
0.1.1 0 / 0
0.1.0 0 / 0

v3.0.5

2 findings
HIGH New obfuscated file: ControlWrapper-CilCgWUv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.4

2 findings
HIGH New obfuscated file: ControlWrapper-CilCgWUv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.3

2 findings
HIGH New obfuscated file: ControlWrapper-CilCgWUv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.2

2 findings
HIGH New obfuscated file: ControlWrapper-Ckzwap0M.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.