@kong-ui-public/documentation
A set of Kong UI components for displaying documents.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/index-CNUFa5l3.js | AI (source-diff): Network+exec pattern from bundled mermaid/markdown renderer, not dropper malware. | ai | |
| source-diff | obfuscated-file:dist/graphql-BSO8hVnT-C6Okg5tI.js | AI (source-diff): Vite-bundled syntax grammar JSON; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/go-DpaXbCNA-DqSXHrGo.js | AI (source-diff): Vite-bundled syntax grammar JSON; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/flowDiagram-I6XJVG4X-B23Smlxp-Em0XNk8h.js | AI (source-diff): Vite-bundled mermaid diagram chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/css-CJQ-rcMF-B_2PRTA_.js | AI (source-diff): Vite-bundled syntax grammar JSON; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/csharp-Cy04UeDC-OaGPefhL.js | AI (source-diff): Vite-bundled syntax grammar JSON; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/c4Diagram-AAUBKEIU-ftdwlfdB-BLRF4Pf5.js | AI (source-diff): Vite-bundled mermaid diagram chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/c-GOwUpV7U-DMPKLUI8.js | AI (source-diff): Vite-bundled syntax grammar JSON; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/astro-D8QEIUE9-nzvtSwAQ.js | AI (source-diff): Vite-bundled syntax grammar JSON; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-CNUFa5l3.js | AI (source-diff): Main Vite bundle for documentation component; minified but not malicious. | ai | |
| source-diff | obfuscated-file:dist/http-DRk-iX-V-DQ76ihB0.js | AI (source-diff): Vite-bundled syntax grammar JSON; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/html-DdIT5Pi9-C35UyBqr.js | AI (source-diff): Vite-bundled syntax grammar JSON; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/haskell-BDLr0yXS-BlmVjKNy.js | AI (source-diff): Vite-bundled syntax grammar JSON; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/handlebars-tnt1-4s--xVtJSIx5.js | AI (source-diff): Vite-bundled syntax grammar JSON; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/haml-DizLz-gS-BWwS-eha.js | AI (source-diff): Vite-bundled syntax grammar JSON; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/c4Diagram-AAMF2YG6-CKwlop6T-biDHxtgF.js | AI (source-diff): Standard Vite-minified Mermaid diagram bundle; content is readable diagram grammar, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/requirementDiagram-EGVEC5DT-CnnVFZwh-D9sZFwwg.js | AI (source-diff): Standard Vite-minified Mermaid diagram bundle; legitimate build output. | ai | |
| source-diff | obfuscated-file:dist/quadrantDiagram-YPSRARAO-BQtyf3HP-D7rZGp1l.js | AI (source-diff): Standard Vite-minified Mermaid diagram bundle; legitimate build output. | ai | |
| source-diff | obfuscated-file:dist/erDiagram-HZWUO2LU-DRB4Mbtv-CgU99FCL.js | AI (source-diff): Standard Vite-minified Mermaid diagram bundle; legitimate build output. | ai | |
| source-diff | obfuscated-file:dist/mermaid-parser.core-DRkTy7co-D3k_lOFL.js | AI (source-diff): Mermaid parser core bundle; minified but content is readable lodash/parser code. | ai | |
| source-diff | net-exec-file:dist/index-DeBlJN4f.js | AI (source-diff): Vue component bundle; network calls are API interactions, dynamic execution is Vue's reactivity system — not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-DeBlJN4f.js | AI (source-diff): Main Vite bundle with Vue imports and i18n strings; readable content confirms legitimate build output. | ai | |
| source-diff | obfuscated-file:dist/flowDiagram-THRYKUMA-Cca2217c-CyDxFUag.js | AI (source-diff): Standard Vite-minified Mermaid diagram bundle; legitimate build output. | ai | |
| source-diff | obfuscated-file:dist/sequenceDiagram-WFGC7UMF-ChsW9bN4-D52efQBS.js | AI (source-diff): Standard Vite-minified Mermaid diagram bundle; legitimate build output. | ai | |
| source-diff | obfuscated-file:dist/mermaid-parser.core-DtLRLmJt-Bs8fzU82.js | AI (source-diff): Minified mermaid parser bundle; legitimate build artifact. | ai | |
| source-diff | obfuscated-file:dist/c4Diagram-AHTNJAMY-D1CqyEQ6-B0R-a6pf.js | AI (source-diff): Minified mermaid diagram bundle; legitimate build artifact for this package. | ai | |
| source-diff | obfuscated-file:dist/erDiagram-SMLLAGMA-23hRKyIy-B-dChHLQ.js | AI (source-diff): Minified mermaid diagram bundle; legitimate build artifact. | ai | |
| source-diff | obfuscated-file:dist/flowDiagram-DWJPFMVM-BeSa8cQn-B2__M71K.js | AI (source-diff): Minified mermaid diagram bundle; legitimate build artifact. | ai | |
| source-diff | obfuscated-file:dist/index-Bh-wTBlD.js | AI (source-diff): Minified main bundle with Vue/i18n imports; legitimate build artifact. | ai | |
| source-diff | obfuscated-file:dist/quadrantDiagram-34T5L4WZ-Cfwapd1Q-CS_lKY3k.js | AI (source-diff): Minified mermaid diagram bundle; legitimate build artifact. | ai | |
| source-diff | obfuscated-file:dist/requirementDiagram-MS252O5E-Bimzbn3B-B-e5vK9F.js | AI (source-diff): Minified mermaid diagram bundle; legitimate build artifact. | ai | |
| source-diff | net-exec-file:dist/cytoscape.esm-BjnMFxuP-CWlRmT1g.js | AI (source-diff): Cytoscape.js graph library bundle; network+exec pattern is false positive for this visualization library. | ai | |
| source-diff | net-exec-file:dist/index-Bh-wTBlD.js | AI (source-diff): Main Vue component bundle; net+exec pattern is false positive for legitimate UI component. | ai | |
| source-diff | obfuscated-file:dist/requirementDiagram-MS252O5E-kbyTwFM7-uVRo-sbb.js | AI (source-diff): Standard Vite minified Mermaid diagram bundle; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/quadrantDiagram-34T5L4WZ-BGiKwrld-lckIOaIT.js | AI (source-diff): Standard Vite minified Mermaid diagram bundle; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/mermaid-parser.core-CyLOoIom-x9WJrfZ4.js | AI (source-diff): Standard Vite minified Mermaid parser bundle; not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/index-DQ-TXxrJ.js | AI (source-diff): False positive on Vite-bundled Vue component; no actual dropper/loader behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/index-DQ-TXxrJ.js | AI (source-diff): Standard Vite minified main bundle with Vue/Kong imports; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/flowDiagram-DWJPFMVM-Hi4kVuUg-C0bJlM16.js | AI (source-diff): Standard Vite minified Mermaid diagram bundle; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/erDiagram-SMLLAGMA-DqpeRG8q-C6pwKkwF.js | AI (source-diff): Standard Vite minified Mermaid diagram bundle; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/c4Diagram-AHTNJAMY-CoIcDDlQ-DOuHA4wJ.js | AI (source-diff): Standard Vite minified Mermaid diagram bundle; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/sequenceDiagram-FGHM5R23-eJlHKiCJ-CHkqRjjz.js | AI (source-diff): Standard Vite minified Mermaid diagram bundle; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/c4Diagram-AHTNJAMY-CoIcDDlQ-mAGkT4bn.js | AI (source-diff): Minified mermaid diagram renderer bundle; expected output for this package. | ai | |
| source-diff | net-exec-file:dist/index-BHz_s4bq.js | AI (source-diff): False positive on bundled Vue component code; no actual dropper/loader behavior present. | ai | |
| source-diff | obfuscated-file:dist/index-BHz_s4bq.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Vue component library; not malicious obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New mermaid diagram type bundles added; expected growth pattern for this package. | ai | |
| source-diff | encoded-string-file:dist/documentation.umd.js | AI (source-diff): Long encoded strings in UMD bundle are expected from Vite build output for this component library. | ai | |
| source-diff | obfuscated-file:dist/requirementDiagram-MS252O5E-kbyTwFM7-BxWs0bV9.js | AI (source-diff): Minified mermaid diagram renderer bundle; expected output for this package. | ai | |
| source-diff | obfuscated-file:dist/quadrantDiagram-34T5L4WZ-BGiKwrld-B1OMDwUy.js | AI (source-diff): Minified mermaid diagram renderer bundle; expected output for this package. | ai | |
| source-diff | obfuscated-file:dist/flowDiagram-DWJPFMVM-Hi4kVuUg-inYUChHw.js | AI (source-diff): Minified mermaid diagram renderer bundle; expected output for this package. | ai | |
| source-diff | obfuscated-file:dist/erDiagram-SMLLAGMA-DqpeRG8q-DV4bMkrn.js | AI (source-diff): Minified mermaid diagram renderer bundle; expected output for this package. | ai | |
| source-diff | obfuscated-file:dist/sequenceDiagram-FGHM5R23-eJlHKiCJ-BoJqtc1E.js | AI (source-diff): Minified mermaid diagram renderer bundle; expected output for this package. | ai | |
| source-diff | obfuscated-file:dist/mermaid-parser.core-CyLOoIom-CwJC_DlH.js | AI (source-diff): Minified mermaid parser bundle; expected output for this package. | ai | |
| dependencies | unvetted-dep:@kong/markdown | AI (dependencies): Same Kong org dependency; consistent across versions of this package. | ai | |
| phantom-deps | phantom-dep:@kong-ui-public/entities-shared | AI (phantom-deps): Same org scope; phantom-dep heuristic unreliable for Vue component packages with template-only usage. | ai | |
| phantom-deps | phantom-dep:@kong/icons | AI (phantom-deps): Same-org Kong dep; likely used in templates/config rather than direct JS imports — stable false positive for this package. | ai |
Versions (showing 100 of 104)
| Version | Deps | Published |
|---|---|---|
| 1.5.67 | 3 / 5 | |
| 1.5.66 | 3 / 5 | |
| 1.5.65 | 3 / 5 | |
| 1.5.64 | 3 / 5 | |
| 1.5.63 | 3 / 5 | |
| 1.5.62 | 3 / 5 | |
| 1.5.61 | 3 / 5 | |
| 1.5.60 | 3 / 5 | |
| 1.5.59 | 3 / 5 | |
| 1.5.58 | 3 / 5 | |
| 1.5.57 | 3 / 5 | |
| 1.5.56 | 3 / 5 | |
| 1.5.55 | 3 / 5 | |
| 1.5.54 | 3 / 5 | |
| 1.5.53 | 3 / 5 | |
| 1.5.52 | 3 / 5 | |
| 1.5.51 | 3 / 5 | |
| 1.5.50 | 3 / 5 | |
| 1.5.49 | 3 / 5 | |
| 1.5.48 | 3 / 5 | |
| 1.5.47 | 3 / 5 | |
| 1.5.46 | 3 / 5 | |
| 1.5.45 | 3 / 5 | |
| 1.5.43 | 3 / 5 | |
| 1.5.42 | 3 / 5 | |
| 1.5.41 | 3 / 5 | |
| 1.5.39 | 3 / 5 | |
| 1.5.38 | 3 / 5 | |
| 1.5.37 | 3 / 5 | |
| 1.5.36 | 3 / 5 | |
| 1.5.35 | 3 / 5 | |
| 1.5.34 | 3 / 5 | |
| 1.5.33 | 3 / 5 | |
| 1.5.32 | 3 / 5 | |
| 1.5.31 | 3 / 5 | |
| 1.5.30 | 3 / 5 | |
| 1.5.29 | 3 / 5 | |
| 1.5.28 | 3 / 5 | |
| 1.5.27 | 3 / 5 | |
| 1.5.26 | 3 / 5 | |
| 1.5.25 | 3 / 5 | |
| 1.5.24 | 3 / 5 | |
| 1.5.23 | 3 / 5 | |
| 1.5.22 | 3 / 5 | |
| 1.5.21 | 3 / 5 | |
| 1.5.20 | 3 / 5 | |
| 1.5.19 | 3 / 5 | |
| 1.5.18 | 3 / 5 | |
| 1.5.17 | 3 / 5 | |
| 1.5.16 | 3 / 5 | |
| 1.5.15 | 3 / 5 | |
| 1.5.14 | 3 / 5 | |
| 1.5.13 | 3 / 5 | |
| 1.5.12 | 3 / 5 | |
| 1.5.11 | 3 / 5 | |
| 1.5.10 | 3 / 5 | |
| 1.5.9 | 3 / 5 | |
| 1.5.8 | 3 / 5 | |
| 1.5.7 | 3 / 5 | |
| 1.5.6 | 3 / 5 | |
| 1.5.5 | 3 / 5 | |
| 1.5.4 | 3 / 5 | |
| 1.5.3 | 3 / 5 | |
| 1.5.2 | 3 / 5 | |
| 1.5.1 | 3 / 5 | |
| 1.5.0 | 3 / 5 | |
| 1.4.52 | 3 / 5 | |
| 1.4.51 | 3 / 5 | |
| 1.4.50 | 3 / 5 | |
| 1.4.49 | 3 / 5 | |
| 1.4.48 | 3 / 5 | |
| 1.4.47 | 3 / 5 | |
| 1.4.46 | 3 / 5 | |
| 1.4.45 | 3 / 5 | |
| 1.4.44 | 3 / 5 | |
| 1.4.43 | 3 / 5 | |
| 1.4.42 | 3 / 5 | |
| 1.4.41 | 3 / 5 | |
| 1.4.40 | 3 / 5 | |
| 1.4.39 | 3 / 5 | |
| 1.4.38 | 3 / 5 | |
| 1.4.37 | 3 / 5 | |
| 1.4.36 | 3 / 5 | |
| 1.4.35 | 3 / 5 | |
| 1.4.34 | 3 / 5 | |
| 1.4.33 | 3 / 5 | |
| 1.4.32 | 3 / 5 | |
| 1.4.31 | 3 / 5 | |
| 1.4.30 | 3 / 5 | |
| 1.4.29 | 3 / 5 | |
| 1.4.28 | 3 / 5 | |
| 1.4.27 | 3 / 5 | |
| 1.4.26 | 3 / 5 | |
| 1.4.25 | 3 / 5 | |
| 1.4.24 | 3 / 5 | |
| 1.4.23 | 3 / 5 | |
| 1.4.22 | 3 / 5 | |
| 1.4.21 | 3 / 5 | |
| 1.4.20 | 3 / 5 | |
| 1.4.19 | 3 / 5 |
v1.5.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.51
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.50
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.49
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.48
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.47
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.42
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.37
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.36
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.35
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.32
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.31
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.