← Home

@lukso/web-components

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

frozemanlukso-networkdzbojenea_vn

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/chunks/index-DIfveR8p.js AI (source-diff): Tailwind/lit bundled CSS/JS build output. ai
source-diff obfuscated-file:dist/chunks/index-QpwaL8ie.js AI (source-diff): Tailwind/lit bundled CSS/JS build output. ai
source-diff obfuscated-file:dist/components/lukso-qr-code/index.cjs AI (source-diff): Bundled third-party qr-code-styling minified UMD, not custom obfuscation; matches new component. ai
phantom-deps phantom-dep:@lukso/core AI (phantom-deps): Same-org scoped dependency, expected. ai
publish-pattern new-deps-added AI (publish-pattern): Established libs (viem, tailwind, marked, etc.) match new UI components added this release. ai
source-diff large-new-source-files AI (source-diff): Bulk icon component files, consistent with package's stated icon library function. ai
source-diff obfuscated-file:dist/components/lukso-icon/vuesax/outline/setting-2.svg.cjs AI (source-diff): Long line is a minified SVG string asset, not true obfuscation. ai
source-diff obfuscated-file:dist/chunks/index-7BmB6zet.js AI (source-diff): Lit/Tailwind bundled component chunk, build output not obfuscation. ai
source-diff obfuscated-file:dist/chunks/index-WbyPQW8n.js AI (source-diff): Lit/Tailwind bundled component chunk, build output not obfuscation. ai
source-diff obfuscated-file:dist/chunks/index-xZkcKMCB.js AI (source-diff): bundled component chunk (lit/tailwind), build output. ai
source-diff obfuscated-file:dist/chunks/index-CWVksY60.js AI (source-diff): bundled component chunk (lit/tailwind), build output. ai
source-diff obfuscated-file:dist/chunks/index-DvaA_XMV.js AI (source-diff): Tailwind CSS build chunk, bundled not obfuscated. ai
source-diff net-exec-file:tools/axe-TH2R_oH7.js AI (source-diff): axe-core accessibility testing lib; no exfil/dropper behavior. ai
source-diff obfuscated-file:tools/axe-TH2R_oH7.js AI (source-diff): Bundled axe-core library, minified not obfuscated. ai
source-diff obfuscated-file:dist/chunks/index-DJzCzdSU.js AI (source-diff): Tailwind CSS build chunk, bundled not obfuscated. ai
source-diff net-exec-file:tools/axe-CMrnqurC.cjs AI (source-diff): axe-core accessibility scanner; no malicious net+exec behavior found. ai
source-diff obfuscated-file:tools/axe-Cc1s6soj.js AI (source-diff): Minified bundle of axe-core dep, not obfuscation. ai
source-diff net-exec-file:tools/axe-Cc1s6soj.js AI (source-diff): axe-core accessibility scanner; no malicious net+exec behavior found. ai
source-diff obfuscated-file:tools/axe-CMrnqurC.cjs AI (source-diff): Minified bundle of axe-core dep, not obfuscation. ai
source-diff net-exec-file:dist/axe-C-H1UVi1.cjs AI (source-diff): False positive: bundler boilerplate, not dropper/loader code. ai
phantom-deps phantom-dep:axe-core AI (phantom-deps): Bundled accessibility testing dep, referenced via config not direct import. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Used indirectly via component config; not a real risk for this UI toolkit. ai
source-diff obfuscated-file:dist/axe-C-H1UVi1.cjs AI (source-diff): CJS build of bundled axe-core, same as JS variant. ai
source-diff net-exec-file:dist/axe-BK9JSROP.js AI (source-diff): False positive: bundler import.meta.url resolution code, no real network+exec malware behavior. ai
source-diff obfuscated-file:dist/axe-BK9JSROP.js AI (source-diff): Bundled axe-core library output, not obfuscation; standard bundler boilerplate in sample. ai
source-diff obfuscated-file:dist/index-V6wvb6SH.js AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement source visible in sample. Normal for this package. ai
source-diff obfuscated-file:dist/index-D8IqXWcZ.cjs AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement source visible in sample. Normal for this package. ai
source-diff obfuscated-file:dist/index-C9vH8YlV.js AI (source-diff): Standard Vite/Rollup minified bundle output for a web-components library; LitElement license headers confirm legitimate build artifact. ai
source-diff obfuscated-file:dist/index-DkfODalz.cjs AI (source-diff): CJS counterpart of the same minified bundle; same reasoning as the ESM file. ai
source-diff net-exec-file:tools/axe-HmsG1pWb.cjs AI (source-diff): axe-core legitimately uses dynamic code execution for accessibility rule evaluation; not a dropper pattern. ai
source-diff obfuscated-file:tools/axe-HmsG1pWb.cjs AI (source-diff): File is a bundled copy of [email protected] (accessibility library); minification is expected, not malicious. ai
source-diff obfuscated-file:dist/index-ai1JMlH_.js AI (source-diff): Standard minified Lit/web-components build output with license headers; not obfuscation. ai
source-diff obfuscated-file:dist/index-sTnZd0lm.cjs AI (source-diff): CJS equivalent of the same minified Lit bundle; not obfuscation. ai
source-diff obfuscated-file:dist/index-KrWvJ44l.cjs AI (source-diff): Minified Lit/LitElement framework bundle (CJS variant); standard build output for this web-components package. ai
source-diff obfuscated-file:dist/index-BWp0TAbf.js AI (source-diff): Minified Lit/LitElement framework bundle; standard build output for this web-components package. ai
source-diff obfuscated-file:tools/axe-RWGhQLPE.js AI (source-diff): Bundled [email protected] ESM distribution; not obfuscated malware. ai
source-diff net-exec-file:tools/axe-Njf3Jvxk.cjs AI (source-diff): axe-core accessibility library bundle; network/exec pattern is from its legitimate browser API usage. ai
source-diff obfuscated-file:tools/axe-Njf3Jvxk.cjs AI (source-diff): Bundled [email protected] minified distribution; not obfuscated malware. ai
source-diff net-exec-file:tools/axe-RWGhQLPE.js AI (source-diff): axe-core accessibility library bundle; network/exec pattern is from its legitimate browser API usage. ai
source-diff obfuscated-file:dist/index-DKXUCmZ9.cjs AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement license headers visible; not obfuscated. ai
source-diff obfuscated-file:dist/index-LyJ1o9RN.js AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement license headers visible; not obfuscated. ai
source-diff obfuscated-file:dist/components/lukso-markdown/index.js AI (source-diff): Minified build output of the marked markdown parser; standard bundling for this UI component library. ai
source-diff obfuscated-file:dist/components/lukso-markdown/index.cjs AI (source-diff): Minified build output of the marked markdown parser; standard bundling for this UI component library. ai
source-diff obfuscated-file:dist/index-C1D2PVva.cjs AI (source-diff): Standard minified Lit framework bundle output; not obfuscated malware. ai
source-diff obfuscated-file:dist/index-Ga3DorGn.js AI (source-diff): Standard minified Lit framework bundle output; not obfuscated malware. ai
source-diff obfuscated-file:dist/index-DqZeY5Ft.js AI (source-diff): Standard minified build output (LitElement/BSD-3-Clause); not obfuscation. Stable pattern for this package. ai
bogus-package bogus-package AI (bogus-package): Scoped org package bundles deps; missing metadata signals are false positives for this established library. ai
source-diff obfuscated-file:dist/index-CuduEaB2.cjs AI (source-diff): Standard minified build output (LitElement/BSD-3-Clause); not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/index-DFCjzim8.js AI (source-diff): Standard Rollup/Vite minified bundle output with readable LitElement source; not obfuscated. ai
source-diff obfuscated-file:dist/index-ClAf3gfo.cjs AI (source-diff): Standard Rollup/Vite minified bundle output with readable LitElement source; not obfuscated. ai
source-diff net-exec-file:tools/axe-Dj3cSaX8.cjs AI (source-diff): axe-core uses network APIs for accessibility testing; not dropper behavior. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance; legitimate automation migration. ai
source-diff obfuscated-file:tools/axe-Dj3cSaX8.cjs AI (source-diff): Bundled axe-core v4.11.1 accessibility library; minified by design, copyright header confirms identity. ai
phantom-deps phantom-dep:web3-utils AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. ai
phantom-deps phantom-dep:ethereum-blockies-base64 AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. ai
phantom-deps phantom-dep:tailwind-variants AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. ai
phantom-deps phantom-dep:tailwind-merge AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. ai
phantom-deps phantom-dep:tippy.js AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. ai
dependencies unvetted-dep:@lukso/lsp-smart-contracts AI (dependencies): First-party LUKSO dependency; expected and stable for this package across versions. ai
npm-metadata no-description AI (npm-metadata): Long-lived official LUKSO package; missing description is a cosmetic issue, not a risk indicator. ai

Versions (showing 51 of 303)

View all versions
Version Deps Published
1.207.0 16 / 0
1.206.0 16 / 0
1.205.0 16 / 0
1.204.0 16 / 0
1.203.5 16 / 0
1.203.4 16 / 0
1.203.3 16 / 0
1.203.2 16 / 0
1.203.1 16 / 0
1.203.0 16 / 0
1.202.0 16 / 0
1.201.2 16 / 0
1.201.1 16 / 0
1.201.0 16 / 0
1.200.1 16 / 0
1.200.0 16 / 0
1.199.0 16 / 0
1.198.0 16 / 0
1.197.1 16 / 0
1.197.0 16 / 0
1.196.0 16 / 0
1.195.0 16 / 0
1.194.1 16 / 0
1.194.0 16 / 0
1.192.1 16 / 0
1.192.0 16 / 0
1.191.1 16 / 0
1.191.0 16 / 0
1.190.0 16 / 0
1.189.0 16 / 0
1.188.0 16 / 0
1.187.0 16 / 0
1.186.0 16 / 0
1.185.0 16 / 0
1.184.0 16 / 0
1.183.1 16 / 0
1.183.0 16 / 0
1.182.0 15 / 0
1.181.0 15 / 0
1.180.1 15 / 0
1.180.0 15 / 0
1.179.0 15 / 0
1.178.0 15 / 0
1.177.1 15 / 0
1.177.0 13 / 0
1.176.0 13 / 0
1.175.0 13 / 0
1.174.0 13 / 0
1.173.3 13 / 0
1.173.2 13 / 0
1.173.1 13 / 0

v1.187.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.186.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.185.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.184.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.183.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.183.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.182.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.181.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.180.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.180.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.179.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.178.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.177.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.177.0

5 findings
HIGH New obfuscated file: tools/axe-TH2R_oH7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: tools/axe-TH2R_oH7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/index-7BmB6zet.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/chunks/index-WbyPQW8n.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.176.0

5 findings
HIGH New obfuscated file: tools/axe-TH2R_oH7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: tools/axe-TH2R_oH7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/index-7BmB6zet.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/chunks/index-WbyPQW8n.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.175.0

5 findings
HIGH New obfuscated file: tools/axe-TH2R_oH7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: tools/axe-TH2R_oH7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/index-CWVksY60.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/chunks/index-xZkcKMCB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.174.0

5 findings
HIGH New obfuscated file: tools/axe-TH2R_oH7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: tools/axe-TH2R_oH7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/index-CWVksY60.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/chunks/index-xZkcKMCB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.173.3

5 findings
HIGH New obfuscated file: tools/axe-TH2R_oH7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: tools/axe-TH2R_oH7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/index-CWVksY60.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/chunks/index-xZkcKMCB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.173.2

5 findings
HIGH New obfuscated file: tools/axe-TH2R_oH7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: tools/axe-TH2R_oH7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/index-CWVksY60.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/chunks/index-xZkcKMCB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.173.1

5 findings
HIGH New obfuscated file: tools/axe-TH2R_oH7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: tools/axe-TH2R_oH7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/index-DIfveR8p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/chunks/index-QpwaL8ie.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.