← Home

@guardian/stand

_Find what you need on the (news)stand!_

44
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

guardian-developerscoldlinkakash1810reettaandrew.howe-elysndrsashcorrguardian

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/types/components/intended-audience-signifier/sandbox.d.ts AI (source-diff): Long lines are JSX sandbox code embedded as string literals in a .d.ts declaration file — not obfuscation. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom is declared as both a dependency and peer dependency; phantom-dep is a false positive here. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Guardian monorepo initial publish pattern; 114 versions in registry confirms active org, not throwaway. ai
source-diff obfuscated-file:dist/types/components/menu/sandbox.d.ts AI (source-diff): Long lines are embedded JSX/CSS strings in .d.ts sandbox demo files, not obfuscated malicious code. ai
source-diff obfuscated-file:dist/types/components/icon-button/sandbox.d.ts AI (source-diff): Same pattern: readable JSX/CSS strings in sandbox .d.ts files. ai
source-diff obfuscated-file:dist/types/components/button/sandbox.d.ts AI (source-diff): Long lines are readable JSX/CSS strings embedded in .d.ts sandbox demo files, not obfuscated malware. ai
source-diff obfuscated-file:dist/types/components/icon-link-button/sandbox.d.ts AI (source-diff): Same pattern: readable JSX/CSS strings in sandbox .d.ts files. ai
source-diff obfuscated-file:dist/types/components/link-button/sandbox.d.ts AI (source-diff): Same pattern: readable JSX/CSS strings in sandbox .d.ts files. ai
source-diff obfuscated-file:dist/types/components/text-area/sandbox.d.ts AI (source-diff): Same pattern: embedded sandbox code strings in TypeScript declaration files, not obfuscation. ai
source-diff obfuscated-file:dist/types/components/alert-banner/sandbox.d.ts AI (source-diff): Same pattern: embedded sandbox code strings in TypeScript declaration files, not obfuscation. ai
source-diff obfuscated-file:dist/types/components/checkbox/CheckboxSandbox.d.ts AI (source-diff): Long lines are embedded JSX/CSS string literals in .d.ts sandbox files, not obfuscation. ai
source-diff obfuscated-file:dist/types/components/radio-group/sandbox.d.ts AI (source-diff): Long lines are embedded JSX/CSS string literals in .d.ts sandbox files, not obfuscation. ai
source-diff obfuscated-file:dist/types/components/checkbox/CheckboxGroupSandbox.d.ts AI (source-diff): Long lines are embedded JSX/CSS string literals in .d.ts sandbox files, not obfuscation. ai
typosquat typosquat.levenshtein:zustand AI (typosquat): Legitimate @guardian org design system package; scoped namespace makes typosquatting implausible. ai

Versions (showing 44 of 44)

Version Deps Published
0.0.44 0 / 51
0.0.43 0 / 51
0.0.42 0 / 51
0.0.41 0 / 51
0.0.40 0 / 54
0.0.39 0 / 54
0.0.38 0 / 54
0.0.37 0 / 54
0.0.36 0 / 54
0.0.35 0 / 54
0.0.34 0 / 54
0.0.33 0 / 54
0.0.32 0 / 52
0.0.31 0 / 51
0.0.30 0 / 51
0.0.29 0 / 51
0.0.28 0 / 51
0.0.27 0 / 51
0.0.26 0 / 51
0.0.25 0 / 51
0.0.24 0 / 51
0.0.23 0 / 51
0.0.22 0 / 51
0.0.21 0 / 51
0.0.20 0 / 52
0.0.19 0 / 52
0.0.18 0 / 52
0.0.17 0 / 52
0.0.16 0 / 53
0.0.15 0 / 52
0.0.14 0 / 51
0.0.13 0 / 51
0.0.12 0 / 50
0.0.11 0 / 50
0.0.10 0 / 50
0.0.9 0 / 45
0.0.8 0 / 45
0.0.7 0 / 45
0.0.6 0 / 44
0.0.5 0 / 38
0.0.4 0 / 38
0.0.3 10 / 28
0.0.2 10 / 29
0.0.0 0 / 9

v0.0.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.36

2 findings
HIGH New obfuscated file: dist/types/components/intended-audience-signifier/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.35

2 findings
HIGH New obfuscated file: dist/types/components/intended-audience-signifier/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.34

2 findings
HIGH New obfuscated file: dist/types/components/intended-audience-signifier/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.17

6 findings
HIGH New obfuscated file: dist/types/components/button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/components/icon-button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/components/icon-link-button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/components/link-button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/components/menu/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.16

6 findings
HIGH New obfuscated file: dist/types/components/button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/components/icon-button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/components/icon-link-button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/components/link-button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/components/menu/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.15

5 findings
HIGH New obfuscated file: dist/types/components/button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/components/icon-button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/components/icon-link-button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/types/components/link-button/sandbox.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.