@mastra/playground-ui
Mastra Playground components
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/logs-data-list-Bkf7oWlx.js | AI (source-diff): Standard Vite/Rollup minified React component bundle; not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:dist/logs-data-list-kzBMv1MW.cjs | AI (source-diff): Standard Vite/Rollup minified React component bundle; not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:dist/logs-data-list-Dh6c7URj.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable imports confirm legitimate React UI code. | ai | |
| source-diff | obfuscated-file:dist/logs-data-list-3qmFjBz8.cjs | AI (source-diff): Standard Vite/Rollup minified bundle output; readable imports confirm legitimate React UI code. | ai | |
| source-diff | obfuscated-file:dist/logs-data-list-De4DHIW9.cjs | AI (source-diff): Standard Vite/Rollup minified bundle output; readable imports confirm legitimate React UI code. | ai | |
| source-diff | obfuscated-file:dist/logs-data-list-Be970xP6.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable imports confirm legitimate React UI code. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Package publishes via GitHub Actions CI; human maintainer removal is expected in a CI-only publish model. | ai | |
| phantom-deps | phantom-dep:easy-day-js | AI (phantom-deps): Phantom-dep heuristic; declared in package.json but may be used indirectly via config. Not independently blocking. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-popover | AI (phantom-deps): Radix UI transitive deps in component library; stable pattern. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-collapsible | AI (phantom-deps): Radix UI transitive deps in component library; stable pattern. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-alert-dialog | AI (phantom-deps): Radix UI transitive deps in component library; stable pattern. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-dropdown-menu | AI (phantom-deps): Radix UI transitive deps in component library; stable pattern. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-tooltip | AI (phantom-deps): Radix UI transitive deps in component library; stable pattern. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Both new deps are established Radix UI / TanStack packages; consistent with normal UI library growth. | ai | |
| phantom-deps | phantom-dep:@codemirror/merge | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:@hookform/resolvers | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-tabs | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:prism-react-renderer | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:@codemirror/lang-json | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:@codemirror/autocomplete | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:@codemirror/language | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:cmdk | AI (phantom-deps): UI library bundles deps referenced in config; phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Same pattern — config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:recharts | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:superjson | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:@lukeed/uuid | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:use-debounce | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:@base-ui/react | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:@dagrejs/dagre | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:react-markdown | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| phantom-deps | phantom-dep:@lezer/highlight | AI (phantom-deps): Config-referenced dep in bundled UI library. | ai | |
| dependencies | unvetted-dep:@radix-ui/react-hover-card | AI (dependencies): @radix-ui/react-hover-card is a standard Radix UI primitive; consistent with the many other @radix-ui/* deps in this package. | ai | |
| phantom-deps | phantom-dep:@assistant-ui/react-ui | AI (phantom-deps): Used in config/build setup rather than direct imports; stable false positive for this UI component library package. | ai |
Versions (showing 42 of 42)
| Version | Deps | Published |
|---|---|---|
| 43.0.0 | 29 / 40 | |
| 42.0.1 | 29 / 40 | |
| 42.0.0 | 29 / 40 | |
| 41.0.0 | 29 / 40 | |
| 40.0.1 | 29 / 39 | |
| 40.0.0 | 29 / 39 | |
| 39.0.0 | 29 / 39 | |
| 38.0.0 | 29 / 39 | |
| 37.0.0 | 29 / 39 | |
| 36.0.0 | 29 / 38 | |
| 35.0.0 | 29 / 38 | |
| 34.0.0 | 29 / 38 | |
| 33.0.0 | 29 / 38 | |
| 32.0.2 | 30 / 37 | |
| 32.0.1 | 30 / 37 | |
| 32.0.0 | 30 / 37 | |
| 31.0.0 | 30 / 37 | |
| 30.0.1 | 36 / 37 | |
| 30.0.0 | 36 / 37 | |
| 29.0.0 | 42 / 37 | |
| 28.0.1 | 44 / 37 | |
| 28.0.0 | 44 / 37 | |
| 27.0.1 | 44 / 35 | |
| 27.0.0 | 44 / 35 | |
| 26.0.1 | 43 / 35 | |
| 26.0.0 | 43 / 35 | |
| 25.0.0 | 43 / 33 | |
| 24.0.2 | 43 / 33 | |
| 24.0.1 | 43 / 33 | |
| 24.0.0 | 43 / 33 | |
| 23.0.2 | 43 / 31 | |
| 23.0.1 | 43 / 31 | |
| 23.0.0 | 43 / 31 | |
| 22.1.2 | 43 / 31 | |
| 22.1.1 | 63 / 37 | |
| 22.1.0 | 63 / 37 | |
| 22.0.1 | 62 / 37 | |
| 22.0.0 | 62 / 37 | |
| 21.0.0 | 62 / 37 | |
| 20.0.2 | 62 / 35 | |
| 20.0.1 | 62 / 35 | |
| 20.0.0 | 62 / 35 |
v43.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v42.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v42.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v41.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v40.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v40.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v39.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v38.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.