← Home

@gympass/yoga

Gympass component library

23
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

tckguilhermecardoso-gympasslm2almeidarafaelcoletagympassgympass_josie_botnypacheconaabrazheyvitothalescostarollo-wellhub

Keywords

Gympasscomponentsstyled-componentsreactdesign-system

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:react-google-font-loader AI (dependencies): Established utility dep used consistently across versions of this design system package. ai
dependencies unvetted-dep:@gympass/yoga-common AI (dependencies): Same-org monorepo sub-package; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@gympass/yoga-system AI (dependencies): Same-org monorepo sub-package; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@gympass/yoga-tokens AI (dependencies): Same-org monorepo sub-package; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@gympass/yoga-helpers AI (dependencies): Same-org monorepo sub-package; stable pattern across all versions of this package. ai
dependencies unvetted-dep:@gympass/yoga-illustrations AI (dependencies): Same-org monorepo sub-package; stable pattern across all versions of this package. ai
source-diff encoded-string-file:cjs/Input/web/data-images.js AI (source-diff): Encoded strings are SVG icons and a flags sprite PNG via encodeURI(); standard pattern for this UI component library. ai
source-diff encoded-string-file:esm/Input/web/data-images.js AI (source-diff): Same as CJS counterpart — SVG/PNG assets encoded for inline use; not a malicious payload. ai
phantom-deps phantom-dep:@gympass/yoga-illustrations AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for monorepo re-exports. ai
phantom-deps phantom-dep:date-fns AI (phantom-deps): date-fns is a declared runtime dep; may be used indirectly via re-exports or config files in this monorepo package. ai
typosquat typosquat.levenshtein:koa AI (typosquat): Scoped package @gympass/yoga is a well-known design system; Levenshtein match to 'koa' is a clear false positive. ai

Versions (showing 23 of 23)

Version Deps Published
7.144.3 17 / 6
7.144.2 17 / 6
7.144.1 17 / 6
7.144.0 17 / 6
7.143.5 17 / 6
7.143.4 17 / 6
7.143.3 17 / 6
7.143.2 17 / 6
7.143.1 17 / 6
7.143.0 17 / 6
7.142.0 17 / 6
7.141.0 17 / 6
7.140.0 17 / 6
7.139.1 17 / 6
7.139.0 17 / 6
7.138.0 17 / 6
7.137.2 17 / 6
7.137.1 17 / 6
7.137.0 17 / 6
7.136.0 17 / 6
7.135.7 17 / 6
7.134.1 17 / 6
7.134.0 17 / 6

v7.144.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.144.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.144.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.143.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.143.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.143.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.143.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.142.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.141.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.140.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.139.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.139.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.138.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.137.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.137.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.137.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.136.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.135.7

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: gympass_josie_bot → GitHub Actions (on 2026-01-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (gympass_josie_bot) on 2026-01-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v7.134.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.134.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.