← Home

@netlify/spark-ui

Assets, design tokens, components, and utilities

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

seanrobertsbiilmanneduardoboucasnetlify-botsarahettermikewenkathmbeckhrishikeshkvitaliyrberdavyouvalvserhalp-netlifydomitriusanthonyakardettbarnseancdavismlgualtieri-gatsby

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/chunks/AskNetlify.BiMhcpol.js AI (source-diff): Vite build output; minified but not obfuscated — readable imports and component names visible in sample. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.CNYCiNSp.js AI (source-diff): Vite-bundled chunk with readable imports and standard class patterns; minification artifact, not obfuscation. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.5UxkBfoE.js AI (source-diff): Vite build output; minified but clearly structured with named internal imports, not malicious obfuscation. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.hLTCaFLd.js AI (source-diff): Standard Vite minified bundle chunk; code sample shows normal Preact/ES module patterns, not obfuscation. ai
source-diff obfuscated-file:dist/chunks/ChatInterface.EQAPs01R.js AI (source-diff): Standard Vite build output; readable imports and logic, no malicious patterns. Expected for this UI component library. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.lrswYyKn.js AI (source-diff): Standard Vite minified bundle output; readable imports and component names confirm legitimate build artifact. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.1ejGUA_O.js AI (source-diff): Vite-minified UI component bundle; readable imports and structure confirm legitimate build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/chunks/ChatInterface.BLB99yBP.js AI (source-diff): Vite build output; minified but readable ES module code with clear Preact/component imports, not obfuscated. ai
source-diff obfuscated-file:dist/chunks/ChatInterface.BD7rlv4H.js AI (source-diff): Vite-bundled UI chunk with readable imports; minified but not obfuscated, consistent with build tooling for this package. ai
dependencies unvetted-dep:@kapaai/react-sdk AI (dependencies): Intentional addition for AskNetlify AI chat feature; consistent with new bundle files in this version. ai
dependencies unvetted-dep:vite-plugin-lib-inject-css AI (dependencies): Common Vite library build plugin; consistent with this package's build setup. ai
dependencies unvetted-dep:@preact/preset-vite AI (dependencies): Standard Preact/Vite build tooling; expected for a Preact component library. ai
bogus-package bogus-package AI (bogus-package): Scoped @netlify package with 139 versions and 2.1k downloads; clearly not spam despite missing metadata. ai
phantom-deps phantom-dep:@astro-community/astro-embed-youtube AI (phantom-deps): Astro integration referenced in config; stable false positive. ai
phantom-deps phantom-dep:@shikijs/transformers AI (phantom-deps): Build/syntax-highlighting utility referenced in config only; stable false positive for this package. ai
phantom-deps phantom-dep:vite-tsconfig-paths AI (phantom-deps): Vite plugin referenced in build config only; stable false positive for this package. ai
phantom-deps phantom-dep:@preact/preset-vite AI (phantom-deps): Vite plugin referenced in build config only; stable false positive for this package. ai
phantom-deps phantom-dep:vite-plugin-dts AI (phantom-deps): vite-plugin-dts is a build tool in config files only; stable false positive for this Vite-based library. ai
phantom-deps phantom-dep:vite AI (phantom-deps): vite is a build tool referenced in config files only; phantom-dep is a stable false positive for this Vite-based component library. ai
phantom-deps phantom-dep:glob AI (phantom-deps): glob is a build utility referenced in config/scripts only; stable false positive for this package. ai
phantom-deps phantom-dep:vite-plugin-lib-inject-css AI (phantom-deps): Vite plugin referenced in build config only; stable false positive for this package. ai

Versions (showing 51 of 63)

View all versions
Version Deps Published
1.24.1 4 / 24
1.24.0 11 / 9
1.23.1 11 / 9
1.23.0 11 / 9
1.22.0 11 / 9
1.21.1 10 / 9
1.20.1 10 / 9
1.20.0 10 / 9
1.19.0 10 / 9
1.18.0 10 / 9
1.17.6 10 / 9
1.17.5 10 / 9
1.17.4 10 / 9
1.17.3 10 / 9
1.17.2 10 / 9
1.17.1 10 / 9
1.17.0 10 / 9
1.16.0 10 / 9
1.15.1 10 / 9
1.15.0 10 / 9
1.14.6 10 / 9
1.14.5 10 / 9
1.14.4 10 / 9
1.14.3 10 / 9
1.14.2 10 / 9
1.14.1 10 / 9
1.14.0 10 / 9
1.13.3 10 / 9
1.13.2 10 / 9
1.13.1 10 / 9
1.13.0 10 / 9
1.12.4 10 / 9
1.12.3 10 / 9
1.12.2 10 / 9
1.12.1 10 / 9
1.12.0 10 / 9
1.11.0 10 / 9
1.10.0 10 / 9
1.9.1 10 / 9
1.9.0 10 / 9
1.8.7 10 / 9
1.8.6 10 / 9
1.8.5 10 / 9
1.8.4 10 / 9
1.8.3 10 / 9
1.8.2 10 / 9
1.8.1 10 / 9
1.8.0 10 / 9
1.6.0 8 / 9
1.5.0 8 / 9
1.4.5 8 / 9

v1.24.1

2 findings
HIGH New obfuscated file: dist/chunks/AskNetlify.BiMhcpol.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.24.0

2 findings
HIGH New obfuscated file: dist/chunks/AskNetlify.BiMhcpol.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.21.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.17.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.15.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.5

2 findings
HIGH New obfuscated file: dist/chunks/AskNetlify.5UxkBfoE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.14.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.14.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.0

2 findings
HIGH New obfuscated file: dist/chunks/AskNetlify.hLTCaFLd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.13.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.0

2 findings
HIGH New obfuscated file: dist/chunks/AskNetlify.CNYCiNSp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.12.4

2 findings
HIGH New obfuscated file: dist/chunks/AskNetlify.1ejGUA_O.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.12.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.0

2 findings
HIGH New obfuscated file: dist/chunks/AskNetlify.lrswYyKn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.0

2 findings
HIGH New obfuscated file: dist/chunks/ChatInterface.EQAPs01R.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.10.0

2 findings
HIGH New obfuscated file: dist/chunks/ChatInterface.EQAPs01R.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.5

2 findings
HIGH New obfuscated file: dist/chunks/ChatInterface.BD7rlv4H.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.4

2 findings
HIGH New obfuscated file: dist/chunks/ChatInterface.BD7rlv4H.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.3

2 findings
HIGH New obfuscated file: dist/chunks/ChatInterface.BLB99yBP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.