@gympass/yoga
Gympass component library
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:react-google-font-loader | AI (dependencies): Established utility dep used consistently across versions of this design system package. | ai | |
| dependencies | unvetted-dep:@gympass/yoga-common | AI (dependencies): Same-org monorepo sub-package; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@gympass/yoga-system | AI (dependencies): Same-org monorepo sub-package; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@gympass/yoga-tokens | AI (dependencies): Same-org monorepo sub-package; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@gympass/yoga-helpers | AI (dependencies): Same-org monorepo sub-package; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@gympass/yoga-illustrations | AI (dependencies): Same-org monorepo sub-package; stable pattern across all versions of this package. | ai | |
| source-diff | encoded-string-file:cjs/Input/web/data-images.js | AI (source-diff): Encoded strings are SVG icons and a flags sprite PNG via encodeURI(); standard pattern for this UI component library. | ai | |
| source-diff | encoded-string-file:esm/Input/web/data-images.js | AI (source-diff): Same as CJS counterpart — SVG/PNG assets encoded for inline use; not a malicious payload. | ai | |
| phantom-deps | phantom-dep:@gympass/yoga-illustrations | AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for monorepo re-exports. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): date-fns is a declared runtime dep; may be used indirectly via re-exports or config files in this monorepo package. | ai | |
| typosquat | typosquat.levenshtein:koa | AI (typosquat): Scoped package @gympass/yoga is a well-known design system; Levenshtein match to 'koa' is a clear false positive. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 7.144.3 | 17 / 6 | |
| 7.144.2 | 17 / 6 | |
| 7.144.1 | 17 / 6 | |
| 7.144.0 | 17 / 6 | |
| 7.143.5 | 17 / 6 | |
| 7.143.4 | 17 / 6 | |
| 7.143.3 | 17 / 6 | |
| 7.143.2 | 17 / 6 | |
| 7.143.1 | 17 / 6 | |
| 7.143.0 | 17 / 6 | |
| 7.142.0 | 17 / 6 | |
| 7.141.0 | 17 / 6 | |
| 7.140.0 | 17 / 6 | |
| 7.139.1 | 17 / 6 | |
| 7.139.0 | 17 / 6 | |
| 7.138.0 | 17 / 6 | |
| 7.137.2 | 17 / 6 | |
| 7.137.1 | 17 / 6 | |
| 7.137.0 | 17 / 6 | |
| 7.136.0 | 17 / 6 | |
| 7.135.7 | 17 / 6 | |
| 7.134.1 | 17 / 6 | |
| 7.134.0 | 17 / 6 |
v7.144.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.144.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.144.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.143.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.143.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.143.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.143.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.142.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.141.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.140.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.139.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.139.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.138.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.137.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.137.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.137.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.136.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.135.7
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (gympass_josie_bot) on 2026-01-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v7.134.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.134.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.