@icanbwell/native-components
@icanbwell/native-components. repo version: 17.27.3
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-exfil-services | AI (semgrep): Pastebin URL appears only in a code comment explaining a Safari bug, not executed. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Localhost/wildcard entries are WebView origin whitelist constants, not exfil targets. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal scoped package; missing README/repo/keywords is consistent across all versions of this org's packages. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 6.15.2 | 5 / 0 | |
| 6.15.1 | 5 / 0 | |
| 6.15.0 | 5 / 0 | |
| 5.3.1 | 4 / 0 | |
| 5.3.0 | 4 / 0 |
v6.15.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.15.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.15.0
2 findingsURL pointing to known exfiltration/tunneling service (matched inside a comment — likely documentation, not executed code) 4368 | // but for some reason `nativeSlice.call(result, 1, result.length)` (called in 4369 | // the slice polyfill when slicing native arrays) "doesn't work" in safari 9 and > 4370 | // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it. 4371 | for (var j = 1; j < result.length; j++) push$1(captures, maybeToString(result[j])); 4372 | var namedCaptures = result.groups;
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.