@m4l/components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/CommonActions/components/ActionFormSubmitProgrammatic/slots/ActionFormSubmitProgrammaticSlots.d.ts | AI (source-diff): Long-line .d.ts is generated TS type union from Emotion/MUI, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/ColorPicker/slots/ColorPickerSlots.d.ts | AI (source-diff): Long-line .d.ts type declarations from MUI/Emotion generics, not obfuscated code. | ai | |
| source-diff | obfuscated-file:components/ImageSelector/slots/ImageSelectorSlots.d.ts | AI (source-diff): Same pattern: minified type declarations, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/DaysOfWeekPicker/slots/DaysOfWeekPickerSlots.d.ts | AI (source-diff): Long-line .d.ts TypeScript generic type declarations, not obfuscated code. | ai | |
| source-diff | obfuscated-file:components/ObjectLogs/slots/ObjectLogsSlots.d.ts | AI (source-diff): Long-line .d.ts type declarations, not obfuscated executable code. | ai | |
| source-diff | obfuscated-file:components/DaysOfMonthPicker/slots/DaysOfMonthPickerSlots.d.ts | AI (source-diff): Long-line .d.ts type declarations, not obfuscated executable code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected growth for a large component library adding a new picker module. | ai | |
| source-diff | obfuscated-file:components/extended/React-resizable-panels/slots/SplitLayoutSlots.d.ts | AI (source-diff): Generated TS declaration file with long type unions, not obfuscated code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @m4l/base is a first-party same-org dep; addition is consistent with existing @m4l/* deps in this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get used only to read a __version string property; not obfuscation, stable pattern for this package. | ai | |
| dependencies | unvetted-dep:react-data-grid | AI (dependencies): react-data-grid beta pinned at a specific version; consistent usage pattern for this package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable pattern across all versions of this internal package; not a malice signal. | ai | |
| phantom-deps | phantom-dep:leaflet-polylinedecorator | AI (phantom-deps): Peer dep for map components; stable false positive. | ai | |
| phantom-deps | phantom-dep:storybook-multilevel-sort | AI (phantom-deps): Dev/storybook dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-virtualized-auto-sizer | AI (phantom-deps): Declared dep for consumers; stable false positive. | ai | |
| phantom-deps | phantom-dep:@geoman-io/leaflet-geoman-free | AI (phantom-deps): Peer dep for map components; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-intersection-observer | AI (phantom-deps): Declared dep for consumers; stable false positive. | ai | |
| phantom-deps | phantom-dep:qs | AI (phantom-deps): UI component library legitimately declares peer/optional deps not directly imported in every file. | ai | |
| phantom-deps | phantom-dep:install | AI (phantom-deps): Same pattern — declared dep for consumers, not a direct import in library source. | ai | |
| phantom-deps | phantom-dep:leaflet | AI (phantom-deps): Leaflet is a peer dep for map components; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@mui/lab | AI (phantom-deps): MUI lab is a peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a standard peer dep for React component libraries. | ai | |
| phantom-deps | phantom-dep:jwt-decode | AI (phantom-deps): Declared dep for consumers; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:atmosphere.js | AI (phantom-deps): Declared dep for consumers; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-leaflet | AI (phantom-deps): Peer dep for map components; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-chartjs-2 | AI (phantom-deps): Peer dep for chart components; stable false positive. | ai | |
| phantom-deps | phantom-dep:leaflet.markercluster | AI (phantom-deps): Peer dep for map components; stable false positive. | ai | |
| phantom-deps | phantom-dep:@googlemaps/js-api-loader | AI (phantom-deps): Peer dep for map components; stable false positive. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal scoped UI library (@m4l/components); missing metadata is consistent across its 1020 versions, not a spam indicator. | ai |
Versions (showing 100 of 365)
| Version | Deps | Published |
|---|---|---|
| 9.4.11 | 48 / 0 | |
| 9.4.10 | 48 / 0 | |
| 9.4.9 | 48 / 0 | |
| 9.4.8 | 48 / 0 | |
| 9.4.7 | 48 / 0 | |
| 9.4.6 | 48 / 0 | |
| 9.4.5 | 48 / 0 | |
| 9.4.4 | 48 / 0 | |
| 9.4.3 | 48 / 0 | |
| 9.4.2 | 48 / 0 | |
| 9.4.1 | 48 / 0 | |
| 9.4.0 | 48 / 0 | |
| 9.3.43 | 48 / 0 | |
| 9.3.41 | 48 / 0 | |
| 9.3.40 | 48 / 0 | |
| 9.3.39 | 48 / 0 | |
| 9.3.38 | 48 / 0 | |
| 9.3.37 | 48 / 0 | |
| 9.3.36 | 48 / 0 | |
| 9.3.35 | 48 / 0 | |
| 9.3.34 | 48 / 0 | |
| 9.3.33 | 48 / 0 | |
| 9.3.32 | 48 / 0 | |
| 9.3.31 | 48 / 0 | |
| 9.3.30 | 48 / 0 | |
| 9.3.29 | 48 / 0 | |
| 9.3.28 | 48 / 0 | |
| 9.3.27 | 48 / 0 | |
| 9.3.26 | 48 / 0 | |
| 9.3.25 | 48 / 0 | |
| 9.3.24 | 48 / 0 | |
| 9.3.23 | 48 / 0 | |
| 9.3.22 | 48 / 0 | |
| 9.3.21 | 48 / 0 | |
| 9.3.20 | 49 / 0 | |
| 9.3.19 | 49 / 0 | |
| 9.3.18 | 49 / 0 | |
| 9.3.17 | 49 / 0 | |
| 9.3.16 | 49 / 0 | |
| 9.3.15 | 49 / 0 | |
| 9.3.14 | 49 / 0 | |
| 9.3.13 | 49 / 0 | |
| 9.3.12 | 49 / 0 | |
| 9.3.11 | 49 / 0 | |
| 9.3.10 | 49 / 0 | |
| 9.3.9 | 49 / 0 | |
| 9.3.8 | 49 / 0 | |
| 9.3.7 | 49 / 0 | |
| 9.3.6 | 49 / 0 | |
| 9.3.5 | 49 / 0 | |
| 9.3.4 | 49 / 0 | |
| 9.3.3 | 49 / 0 | |
| 9.3.2 | 49 / 0 | |
| 9.3.1 | 49 / 0 | |
| 9.3.0 | 49 / 0 | |
| 9.2.65 | 49 / 0 | |
| 9.2.64 | 49 / 0 | |
| 9.2.63 | 49 / 0 | |
| 9.2.62 | 49 / 0 | |
| 9.2.61 | 49 / 0 | |
| 9.2.60 | 49 / 0 | |
| 9.2.59 | 49 / 0 | |
| 9.2.58 | 49 / 0 | |
| 9.2.57 | 49 / 0 | |
| 9.2.56 | 49 / 0 | |
| 9.2.55 | 49 / 0 | |
| 9.2.54 | 49 / 0 | |
| 9.2.53 | 49 / 0 | |
| 9.2.52 | 49 / 0 | |
| 9.2.51 | 49 / 0 | |
| 9.2.50 | 49 / 0 | |
| 9.2.49 | 49 / 0 | |
| 9.2.48 | 54 / 0 | |
| 9.2.47 | 54 / 0 | |
| 9.2.46 | 54 / 0 | |
| 9.2.45 | 54 / 0 | |
| 9.2.44 | 54 / 0 | |
| 9.2.43 | 54 / 0 | |
| 9.2.42 | 54 / 0 | |
| 9.2.41 | 53 / 0 | |
| 9.2.39 | 53 / 0 | |
| 9.2.38 | 53 / 0 | |
| 9.2.37 | 53 / 0 | |
| 9.2.36 | 53 / 0 | |
| 9.2.35 | 53 / 0 | |
| 9.2.34 | 53 / 0 | |
| 9.2.33 | 53 / 0 | |
| 9.2.32 | 53 / 0 | |
| 9.2.31 | 53 / 0 | |
| 9.2.30 | 53 / 0 | |
| 9.2.29 | 53 / 0 | |
| 9.2.28 | 53 / 0 | |
| 9.2.27 | 53 / 0 | |
| 9.2.26 | 53 / 0 | |
| 9.2.25 | 53 / 0 | |
| 9.2.24 | 53 / 0 | |
| 9.2.23 | 53 / 0 | |
| 9.2.22 | 53 / 0 | |
| 9.2.21 | 53 / 0 | |
| 9.2.20 | 53 / 0 |
v9.4.11
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.4.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.4.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.4.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.4.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.4.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.4.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.4.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.4.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.4.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.3.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.3.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.3.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.3.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.3.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.65
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.64
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.63
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.62
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.61
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.60
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.59
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.58
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.57
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.56
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.55
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.54
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.53
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.52
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.51
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.50
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.49
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.47
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.43
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.42
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.