@m4l/components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/CommonActions/components/ActionFormSubmitProgrammatic/slots/ActionFormSubmitProgrammaticSlots.d.ts | AI (source-diff): Long-line .d.ts is generated TS type union from Emotion/MUI, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/ColorPicker/slots/ColorPickerSlots.d.ts | AI (source-diff): Long-line .d.ts type declarations from MUI/Emotion generics, not obfuscated code. | ai | |
| source-diff | obfuscated-file:components/ImageSelector/slots/ImageSelectorSlots.d.ts | AI (source-diff): Same pattern: minified type declarations, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/DaysOfWeekPicker/slots/DaysOfWeekPickerSlots.d.ts | AI (source-diff): Long-line .d.ts TypeScript generic type declarations, not obfuscated code. | ai | |
| source-diff | obfuscated-file:components/ObjectLogs/slots/ObjectLogsSlots.d.ts | AI (source-diff): Long-line .d.ts type declarations, not obfuscated executable code. | ai | |
| source-diff | obfuscated-file:components/DaysOfMonthPicker/slots/DaysOfMonthPickerSlots.d.ts | AI (source-diff): Long-line .d.ts type declarations, not obfuscated executable code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected growth for a large component library adding a new picker module. | ai | |
| source-diff | obfuscated-file:components/extended/React-resizable-panels/slots/SplitLayoutSlots.d.ts | AI (source-diff): Generated TS declaration file with long type unions, not obfuscated code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @m4l/base is a first-party same-org dep; addition is consistent with existing @m4l/* deps in this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get used only to read a __version string property; not obfuscation, stable pattern for this package. | ai | |
| dependencies | unvetted-dep:react-data-grid | AI (dependencies): react-data-grid beta pinned at a specific version; consistent usage pattern for this package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable pattern across all versions of this internal package; not a malice signal. | ai | |
| phantom-deps | phantom-dep:leaflet-polylinedecorator | AI (phantom-deps): Peer dep for map components; stable false positive. | ai | |
| phantom-deps | phantom-dep:storybook-multilevel-sort | AI (phantom-deps): Dev/storybook dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-virtualized-auto-sizer | AI (phantom-deps): Declared dep for consumers; stable false positive. | ai | |
| phantom-deps | phantom-dep:@geoman-io/leaflet-geoman-free | AI (phantom-deps): Peer dep for map components; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-intersection-observer | AI (phantom-deps): Declared dep for consumers; stable false positive. | ai | |
| phantom-deps | phantom-dep:qs | AI (phantom-deps): UI component library legitimately declares peer/optional deps not directly imported in every file. | ai | |
| phantom-deps | phantom-dep:install | AI (phantom-deps): Same pattern — declared dep for consumers, not a direct import in library source. | ai | |
| phantom-deps | phantom-dep:leaflet | AI (phantom-deps): Leaflet is a peer dep for map components; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@mui/lab | AI (phantom-deps): MUI lab is a peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a standard peer dep for React component libraries. | ai | |
| phantom-deps | phantom-dep:jwt-decode | AI (phantom-deps): Declared dep for consumers; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:atmosphere.js | AI (phantom-deps): Declared dep for consumers; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-leaflet | AI (phantom-deps): Peer dep for map components; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-chartjs-2 | AI (phantom-deps): Peer dep for chart components; stable false positive. | ai | |
| phantom-deps | phantom-dep:leaflet.markercluster | AI (phantom-deps): Peer dep for map components; stable false positive. | ai | |
| phantom-deps | phantom-dep:@googlemaps/js-api-loader | AI (phantom-deps): Peer dep for map components; stable false positive. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal scoped UI library (@m4l/components); missing metadata is consistent across its 1020 versions, not a spam indicator. | ai |
Versions (showing 51 of 364)
| Version | Deps | Published |
|---|---|---|
| 9.40.0 | 42 / 0 | |
| 9.39.0 | 42 / 0 | |
| 9.38.0 | 42 / 0 | |
| 9.37.0 | 42 / 0 | |
| 9.36.0 | 42 / 0 | |
| 9.35.0 | 42 / 0 | |
| 9.34.0 | 42 / 0 | |
| 9.33.1 | 39 / 0 | |
| 9.33.0 | 39 / 0 | |
| 9.32.0 | 39 / 0 | |
| 9.31.0 | 39 / 0 | |
| 9.30.2 | 39 / 0 | |
| 9.30.1 | 40 / 0 | |
| 9.30.0 | 40 / 0 | |
| 9.29.0 | 40 / 0 | |
| 9.28.0 | 40 / 0 | |
| 9.27.0 | 40 / 0 | |
| 9.26.0 | 40 / 0 | |
| 9.25.1 | 40 / 0 | |
| 9.25.0 | 40 / 0 | |
| 9.24.0 | 40 / 0 | |
| 9.23.1 | 40 / 0 | |
| 9.23.0 | 40 / 0 | |
| 9.22.3 | 40 / 0 | |
| 9.22.2 | 40 / 0 | |
| 9.22.1 | 40 / 0 | |
| 9.22.0 | 40 / 0 | |
| 9.21.0 | 40 / 0 | |
| 9.20.0 | 40 / 0 | |
| 9.19.0 | 40 / 0 | |
| 9.18.0 | 40 / 0 | |
| 9.17.0 | 40 / 0 | |
| 9.16.0 | 40 / 0 | |
| 9.15.0 | 40 / 0 | |
| 9.14.0 | 40 / 0 | |
| 9.13.0 | 40 / 0 | |
| 9.12.0 | 40 / 0 | |
| 9.11.0 | 40 / 0 | |
| 9.10.1 | 40 / 0 | |
| 9.10.0 | 40 / 0 | |
| 9.9.0 | 40 / 0 | |
| 9.8.0 | 40 / 0 | |
| 9.7.0 | 40 / 0 | |
| 9.6.0 | 40 / 0 | |
| 9.5.14 | 40 / 0 | |
| 9.5.13 | 40 / 0 | |
| 9.5.12 | 40 / 0 | |
| 9.5.11 | 40 / 0 | |
| 9.5.10 | 40 / 0 | |
| 9.5.9 | 40 / 0 | |
| 9.5.8 | 40 / 0 |
v9.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.35.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.34.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.33.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.33.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.30.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.30.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.30.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.29.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.25.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.23.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.20.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.15.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.13.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.12.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.10.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.5.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.5.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.5.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.