← Home

@hydrooj/ui-default

1
Versions
AGPL-3.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

pandadtdyyundefinedmoe

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:base64-decode AI (semgrep): Template filter exposing base64 encode/decode for nunjucks templates; benign utility in this UI package. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires inside bundled AJV library chunk; standard code-gen pattern in schema validators. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Fires inside bundled md-editor-rt chunk; Reflect.get is idiomatic in modern JS frameworks. ai
bogus-package bogus-package AI (bogus-package): Mature monorepo sub-package; missing README/keywords are expected for internal workspace packages. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): fs-extra is a declared runtime dep used in build scripts; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:markdown-it-attrs AI (phantom-deps): markdown-it-attrs is loaded dynamically as a markdown-it plugin; static import analysis misses this. ai

Versions (showing 1 of 1)

Version Deps Published
4.58.0 23 / 107

v4.58.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.