← Home

@kapaai/widget

19
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

joe-kapabauefikapassem

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:framer-motion AI (phantom-deps): Bundled widget; deps consumed via webpack, not direct imports. Stable FP for this package. ai
phantom-deps phantom-dep:@kapaai/utils AI (phantom-deps): Same-org internal package; bundled via webpack. Stable FP for this package. ai
bogus-package bogus-package AI (bogus-package): Minimal README is common for internal/scoped packages; repo URL and structure are legitimate. ai
phantom-deps phantom-dep:chroma-js AI (phantom-deps): Config-referenced color utility; stable for this widget. ai
phantom-deps phantom-dep:js-cookie AI (phantom-deps): Config-referenced cookie utility; stable for this widget. ai
phantom-deps phantom-dep:ts-loader AI (phantom-deps): Build tool referenced in config; stable for this package. ai
phantom-deps phantom-dep:remark-gfm AI (phantom-deps): Config-referenced markdown plugin; stable for this widget. ai
phantom-deps phantom-dep:@mantine/core AI (phantom-deps): UI framework; config-referenced and stable for this widget. ai
phantom-deps phantom-dep:@mantine/form AI (phantom-deps): Mantine form module; config-referenced and stable. ai
phantom-deps phantom-dep:@emotion/cache AI (phantom-deps): Emotion CSS-in-JS; config-referenced and stable. ai
phantom-deps phantom-dep:@emotion/react AI (phantom-deps): Emotion core; config-referenced and stable. ai
phantom-deps phantom-dep:@mantine/hooks AI (phantom-deps): Mantine hooks; config-referenced and stable. ai
phantom-deps phantom-dep:react-markdown AI (phantom-deps): Config-referenced markdown renderer; stable for this widget. ai
phantom-deps phantom-dep:@emotion/styled AI (phantom-deps): Emotion styled; config-referenced and stable. ai
phantom-deps phantom-dep:@mantine/emotion AI (phantom-deps): Mantine emotion integration; config-referenced and stable. ai
phantom-deps phantom-dep:@kapaai/react-sdk AI (phantom-deps): Same-org dependency; stable for this widget. ai
phantom-deps phantom-dep:@emotion/serialize AI (phantom-deps): Emotion serialization; config-referenced and stable. ai
phantom-deps phantom-dep:@tabler/icons-react AI (phantom-deps): Icon library; config-referenced and stable. ai
phantom-deps phantom-dep:prism-react-renderer AI (phantom-deps): Config-referenced syntax highlighting; stable for this widget. ai
phantom-deps phantom-dep:react-syntax-highlighter AI (phantom-deps): Config-referenced syntax highlighting; stable for this widget. ai
phantom-deps phantom-dep:@emotion/utils AI (phantom-deps): Emotion utility; config-referenced and stable. ai
phantom-deps phantom-dep:prismjs AI (phantom-deps): Config-referenced syntax highlighting; stable pattern for this bundled widget. ai
phantom-deps phantom-dep:process AI (phantom-deps): Polyfill for bundled code; stable pattern for this package. ai
phantom-deps phantom-dep:react AI (phantom-deps): React widget library; dependencies are re-exported or used in build config. ai
npm-metadata no-description AI (npm-metadata): Established package with clear purpose; missing description is metadata gap, not malware signal. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): React widget library; dependencies are re-exported or used in build config. ai

Versions (showing 19 of 19)

Version Deps Published
1.73.14 22 / 26
1.73.13 22 / 26
1.73.12 22 / 26
1.73.11 22 / 26
1.73.10 22 / 26
1.73.9 22 / 26
1.73.8 22 / 26
1.73.7 22 / 26
1.73.6 22 / 26
1.73.5 22 / 26
1.73.4 22 / 26
1.73.3 22 / 26
1.73.2 22 / 26
1.73.1 22 / 26
1.73.0 22 / 26
1.72.0 23 / 26
1.71.18 23 / 26
1.71.1 24 / 25
1.51.5 19 / 25

v1.73.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.73.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.73.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.73.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.73.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.72.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.71.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.71.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.51.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.