@lukso/web-components
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/chunks/index-DIfveR8p.js | AI (source-diff): Tailwind/lit bundled CSS/JS build output. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-QpwaL8ie.js | AI (source-diff): Tailwind/lit bundled CSS/JS build output. | ai | |
| source-diff | obfuscated-file:dist/components/lukso-qr-code/index.cjs | AI (source-diff): Bundled third-party qr-code-styling minified UMD, not custom obfuscation; matches new component. | ai | |
| phantom-deps | phantom-dep:@lukso/core | AI (phantom-deps): Same-org scoped dependency, expected. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Established libs (viem, tailwind, marked, etc.) match new UI components added this release. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Bulk icon component files, consistent with package's stated icon library function. | ai | |
| source-diff | obfuscated-file:dist/components/lukso-icon/vuesax/outline/setting-2.svg.cjs | AI (source-diff): Long line is a minified SVG string asset, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-7BmB6zet.js | AI (source-diff): Lit/Tailwind bundled component chunk, build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-WbyPQW8n.js | AI (source-diff): Lit/Tailwind bundled component chunk, build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-xZkcKMCB.js | AI (source-diff): bundled component chunk (lit/tailwind), build output. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-CWVksY60.js | AI (source-diff): bundled component chunk (lit/tailwind), build output. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-DvaA_XMV.js | AI (source-diff): Tailwind CSS build chunk, bundled not obfuscated. | ai | |
| source-diff | net-exec-file:tools/axe-TH2R_oH7.js | AI (source-diff): axe-core accessibility testing lib; no exfil/dropper behavior. | ai | |
| source-diff | obfuscated-file:tools/axe-TH2R_oH7.js | AI (source-diff): Bundled axe-core library, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/chunks/index-DJzCzdSU.js | AI (source-diff): Tailwind CSS build chunk, bundled not obfuscated. | ai | |
| source-diff | net-exec-file:tools/axe-CMrnqurC.cjs | AI (source-diff): axe-core accessibility scanner; no malicious net+exec behavior found. | ai | |
| source-diff | obfuscated-file:tools/axe-Cc1s6soj.js | AI (source-diff): Minified bundle of axe-core dep, not obfuscation. | ai | |
| source-diff | net-exec-file:tools/axe-Cc1s6soj.js | AI (source-diff): axe-core accessibility scanner; no malicious net+exec behavior found. | ai | |
| source-diff | obfuscated-file:tools/axe-CMrnqurC.cjs | AI (source-diff): Minified bundle of axe-core dep, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/axe-C-H1UVi1.cjs | AI (source-diff): False positive: bundler boilerplate, not dropper/loader code. | ai | |
| phantom-deps | phantom-dep:axe-core | AI (phantom-deps): Bundled accessibility testing dep, referenced via config not direct import. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Used indirectly via component config; not a real risk for this UI toolkit. | ai | |
| source-diff | obfuscated-file:dist/axe-C-H1UVi1.cjs | AI (source-diff): CJS build of bundled axe-core, same as JS variant. | ai | |
| source-diff | net-exec-file:dist/axe-BK9JSROP.js | AI (source-diff): False positive: bundler import.meta.url resolution code, no real network+exec malware behavior. | ai | |
| source-diff | obfuscated-file:dist/axe-BK9JSROP.js | AI (source-diff): Bundled axe-core library output, not obfuscation; standard bundler boilerplate in sample. | ai | |
| source-diff | obfuscated-file:dist/index-V6wvb6SH.js | AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement source visible in sample. Normal for this package. | ai | |
| source-diff | obfuscated-file:dist/index-D8IqXWcZ.cjs | AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement source visible in sample. Normal for this package. | ai | |
| source-diff | obfuscated-file:dist/index-C9vH8YlV.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a web-components library; LitElement license headers confirm legitimate build artifact. | ai | |
| source-diff | obfuscated-file:dist/index-DkfODalz.cjs | AI (source-diff): CJS counterpart of the same minified bundle; same reasoning as the ESM file. | ai | |
| source-diff | net-exec-file:tools/axe-HmsG1pWb.cjs | AI (source-diff): axe-core legitimately uses dynamic code execution for accessibility rule evaluation; not a dropper pattern. | ai | |
| source-diff | obfuscated-file:tools/axe-HmsG1pWb.cjs | AI (source-diff): File is a bundled copy of [email protected] (accessibility library); minification is expected, not malicious. | ai | |
| source-diff | obfuscated-file:dist/index-ai1JMlH_.js | AI (source-diff): Standard minified Lit/web-components build output with license headers; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-sTnZd0lm.cjs | AI (source-diff): CJS equivalent of the same minified Lit bundle; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-KrWvJ44l.cjs | AI (source-diff): Minified Lit/LitElement framework bundle (CJS variant); standard build output for this web-components package. | ai | |
| source-diff | obfuscated-file:dist/index-BWp0TAbf.js | AI (source-diff): Minified Lit/LitElement framework bundle; standard build output for this web-components package. | ai | |
| source-diff | obfuscated-file:tools/axe-RWGhQLPE.js | AI (source-diff): Bundled [email protected] ESM distribution; not obfuscated malware. | ai | |
| source-diff | net-exec-file:tools/axe-Njf3Jvxk.cjs | AI (source-diff): axe-core accessibility library bundle; network/exec pattern is from its legitimate browser API usage. | ai | |
| source-diff | obfuscated-file:tools/axe-Njf3Jvxk.cjs | AI (source-diff): Bundled [email protected] minified distribution; not obfuscated malware. | ai | |
| source-diff | net-exec-file:tools/axe-RWGhQLPE.js | AI (source-diff): axe-core accessibility library bundle; network/exec pattern is from its legitimate browser API usage. | ai | |
| source-diff | obfuscated-file:dist/index-DKXUCmZ9.cjs | AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement license headers visible; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-LyJ1o9RN.js | AI (source-diff): Standard Vite/Rollup minified bundle output; LitElement license headers visible; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/components/lukso-markdown/index.js | AI (source-diff): Minified build output of the marked markdown parser; standard bundling for this UI component library. | ai | |
| source-diff | obfuscated-file:dist/components/lukso-markdown/index.cjs | AI (source-diff): Minified build output of the marked markdown parser; standard bundling for this UI component library. | ai | |
| source-diff | obfuscated-file:dist/index-C1D2PVva.cjs | AI (source-diff): Standard minified Lit framework bundle output; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-Ga3DorGn.js | AI (source-diff): Standard minified Lit framework bundle output; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-DqZeY5Ft.js | AI (source-diff): Standard minified build output (LitElement/BSD-3-Clause); not obfuscation. Stable pattern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped org package bundles deps; missing metadata signals are false positives for this established library. | ai | |
| source-diff | obfuscated-file:dist/index-CuduEaB2.cjs | AI (source-diff): Standard minified build output (LitElement/BSD-3-Clause); not obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/index-DFCjzim8.js | AI (source-diff): Standard Rollup/Vite minified bundle output with readable LitElement source; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-ClAf3gfo.cjs | AI (source-diff): Standard Rollup/Vite minified bundle output with readable LitElement source; not obfuscated. | ai | |
| source-diff | net-exec-file:tools/axe-Dj3cSaX8.cjs | AI (source-diff): axe-core uses network APIs for accessibility testing; not dropper behavior. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance; legitimate automation migration. | ai | |
| source-diff | obfuscated-file:tools/axe-Dj3cSaX8.cjs | AI (source-diff): Bundled axe-core v4.11.1 accessibility library; minified by design, copyright header confirms identity. | ai | |
| phantom-deps | phantom-dep:web3-utils | AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. | ai | |
| phantom-deps | phantom-dep:ethereum-blockies-base64 | AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. | ai | |
| phantom-deps | phantom-dep:tailwind-variants | AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. | ai | |
| phantom-deps | phantom-dep:tailwind-merge | AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. | ai | |
| phantom-deps | phantom-dep:tippy.js | AI (phantom-deps): Declared and used; phantom-dep heuristic is false positive for this package. | ai | |
| dependencies | unvetted-dep:@lukso/lsp-smart-contracts | AI (dependencies): First-party LUKSO dependency; expected and stable for this package across versions. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Long-lived official LUKSO package; missing description is a cosmetic issue, not a risk indicator. | ai |
Versions (showing 51 of 303)
| Version | Deps | Published |
|---|---|---|
| 1.207.0 | 16 / 0 | |
| 1.206.0 | 16 / 0 | |
| 1.205.0 | 16 / 0 | |
| 1.204.0 | 16 / 0 | |
| 1.203.5 | 16 / 0 | |
| 1.203.4 | 16 / 0 | |
| 1.203.3 | 16 / 0 | |
| 1.203.2 | 16 / 0 | |
| 1.203.1 | 16 / 0 | |
| 1.203.0 | 16 / 0 | |
| 1.202.0 | 16 / 0 | |
| 1.201.2 | 16 / 0 | |
| 1.201.1 | 16 / 0 | |
| 1.201.0 | 16 / 0 | |
| 1.200.1 | 16 / 0 | |
| 1.200.0 | 16 / 0 | |
| 1.199.0 | 16 / 0 | |
| 1.198.0 | 16 / 0 | |
| 1.197.1 | 16 / 0 | |
| 1.197.0 | 16 / 0 | |
| 1.196.0 | 16 / 0 | |
| 1.195.0 | 16 / 0 | |
| 1.194.1 | 16 / 0 | |
| 1.194.0 | 16 / 0 | |
| 1.192.1 | 16 / 0 | |
| 1.192.0 | 16 / 0 | |
| 1.191.1 | 16 / 0 | |
| 1.191.0 | 16 / 0 | |
| 1.190.0 | 16 / 0 | |
| 1.189.0 | 16 / 0 | |
| 1.188.0 | 16 / 0 | |
| 1.187.0 | 16 / 0 | |
| 1.186.0 | 16 / 0 | |
| 1.185.0 | 16 / 0 | |
| 1.184.0 | 16 / 0 | |
| 1.183.1 | 16 / 0 | |
| 1.183.0 | 16 / 0 | |
| 1.182.0 | 15 / 0 | |
| 1.181.0 | 15 / 0 | |
| 1.180.1 | 15 / 0 | |
| 1.180.0 | 15 / 0 | |
| 1.179.0 | 15 / 0 | |
| 1.178.0 | 15 / 0 | |
| 1.177.1 | 15 / 0 | |
| 1.177.0 | 13 / 0 | |
| 1.176.0 | 13 / 0 | |
| 1.175.0 | 13 / 0 | |
| 1.174.0 | 13 / 0 | |
| 1.173.3 | 13 / 0 | |
| 1.173.2 | 13 / 0 | |
| 1.173.1 | 13 / 0 |
v1.187.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.186.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.185.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.184.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.183.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.183.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.182.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.181.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.180.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.180.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.179.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.178.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.177.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.177.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.176.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.175.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.174.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.173.3
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.173.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.173.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.