@hanzogui/sandbox-ui
for use testing different ui configurations.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Publisher has strong track record; build script change to 'true' explains environment shift without malicious indicators. | ai | |
| phantom-deps | phantom-dep:solito | AI (phantom-deps): Config-level reference in monorepo; not a real import gap. | ai | |
| phantom-deps | phantom-dep:@hanzo/gui | AI (phantom-deps): Workspace dep referenced in config; expected monorepo pattern. | ai | |
| phantom-deps | phantom-dep:expo-image | AI (phantom-deps): Expo peer/config dep; phantom-dep heuristic not reliable here. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal monorepo UI package; sparse metadata is expected for org-scoped component libraries. | ai | |
| phantom-deps | phantom-dep:expo-constants | AI (phantom-deps): Expo peer/config dep; phantom-dep heuristic not reliable here. | ai | |
| phantom-deps | phantom-dep:@hanzogui/lucide-icons-2 | AI (phantom-deps): Same-org monorepo dep; config reference is expected. | ai | |
| phantom-deps | phantom-dep:@hanzogui/animations-react-native | AI (phantom-deps): Same-org monorepo dep; config reference is expected. | ai | |
| phantom-deps | phantom-dep:@hanzogui/core | AI (phantom-deps): Same-org monorepo dep; config reference is expected. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 7.0.0 | 7 / 2 | |
| 4.4.0 | 7 / 2 | |
| 4.3.1 | 7 / 2 | |
| 3.0.6 | 7 / 2 | |
| 3.0.5 | 7 / 2 |
v4.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zeekay.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.