← Home

@medalsocial/meda

Shared Meda UI shell and runtime package.

21
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

alioftechmedal-pilot

Keywords

tanstack-intent

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/shell/app-shell-auth.js AI (source-diff): File is compiled JSX/TS output with long Tailwind className strings, not obfuscated code. Stable false positive for this build pipeline. ai
phantom-deps phantom-dep:tailwind-merge AI (phantom-deps): Component library re-exports; stable pattern for this package type. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): Component library re-exports; stable pattern for this package type. ai
phantom-deps phantom-dep:cmdk AI (phantom-deps): Component library re-exports; stable pattern for this package type. ai
phantom-deps phantom-dep:vaul AI (phantom-deps): Component library re-exports; stable pattern for this package type. ai
phantom-deps phantom-dep:@base-ui/react AI (phantom-deps): Component library re-exports; stable pattern for this package type. ai
phantom-deps phantom-dep:react-resizable-panels AI (phantom-deps): Component library re-exports; stable pattern for this package type. ai
source-diff obfuscated-file:dist/post-preview/platforms/bluesky.js AI (source-diff): Long lines are bundler output of readable React/TSX components, not obfuscation. ai
source-diff obfuscated-file:dist/post-preview/platforms/discord.js AI (source-diff): Long lines are bundler output of readable React/TSX components, not obfuscation. ai
source-diff obfuscated-file:dist/post-preview/platforms/facebook.js AI (source-diff): Long lines are bundler output of readable React/TSX components, not obfuscation. ai
source-diff obfuscated-file:dist/post-preview/platforms/google-business.js AI (source-diff): Long lines are bundler output of readable React/TSX components, not obfuscation. ai
phantom-deps phantom-dep:@fontsource-variable/geist AI (phantom-deps): Font package imported via CSS/config, not JS; phantom-dep heuristic doesn't cover CSS imports. ai
phantom-deps phantom-dep:@fontsource-variable/geist-mono AI (phantom-deps): Font package imported via CSS/config, not JS; phantom-dep heuristic doesn't cover CSS imports. ai
phantom-deps phantom-dep:class-variance-authority AI (phantom-deps): CVA is a runtime dep used in compiled output; phantom-dep heuristic misses bundled imports. ai

Versions (showing 21 of 21)

Version Deps Published
2.5.0 10 / 44
2.4.2 10 / 44
2.4.1 10 / 43
2.4.0 10 / 43
2.3.0 10 / 40
2.2.0 10 / 40
2.1.0 10 / 40
2.0.0 10 / 39
1.7.0 10 / 39
1.6.0 10 / 39
1.5.0 10 / 39
1.4.0 10 / 39
1.3.0 10 / 39
1.2.0 10 / 39
1.1.2 10 / 36
1.1.1 10 / 36
1.1.0 10 / 36
1.0.0 10 / 36
0.3.0 11 / 22
0.2.0 11 / 21
0.1.1 10 / 15

v2.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.0

5 findings
HIGH New obfuscated file: dist/post-preview/platforms/bluesky.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/post-preview/platforms/discord.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/post-preview/platforms/facebook.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/post-preview/platforms/google-business.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.