← Home

@netlify/spark-ui

Assets, design tokens, components, and utilities

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

netlify-botmikewenyouvalvserhalp-netlifymlgualtieri-gatsby

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern rapid-publish AI (publish-pattern): semantic-release CI pipeline publishes rapidly; not manual/malicious. ai
phantom-deps phantom-dep:@zachleat/filter-container AI (phantom-deps): Matches FilterableGrid export; heuristic false positive. ai
phantom-deps phantom-dep:@zachleat/details-utils AI (phantom-deps): Likely used via component exports; automated semantic-release publisher, low risk. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.jaxhKBOK.js AI (source-diff): Minified Vite/preact bundle output, not true obfuscation; consistent with package's build tooling. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.bx0blyGV.js AI (source-diff): Rollup-bundled preact component, not true obfuscation. ai
dependencies unvetted-dep:@zachleat/filter-container AI (dependencies): Small established utility lib, plausible feature dep. ai
dependencies unvetted-dep:@zachleat/details-utils AI (dependencies): Small established utility lib, plausible feature dep. ai
provenance publisher-changed AI (provenance): CI/CD (GitHub Actions) publish for official Netlify scoped package via semantic-release. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.BiMhcpol.js AI (source-diff): Vite build output; minified but not obfuscated — readable imports and component names visible in sample. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.CNYCiNSp.js AI (source-diff): Vite-bundled chunk with readable imports and standard class patterns; minification artifact, not obfuscation. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.5UxkBfoE.js AI (source-diff): Vite build output; minified but clearly structured with named internal imports, not malicious obfuscation. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.hLTCaFLd.js AI (source-diff): Standard Vite minified bundle chunk; code sample shows normal Preact/ES module patterns, not obfuscation. ai
source-diff obfuscated-file:dist/chunks/ChatInterface.EQAPs01R.js AI (source-diff): Standard Vite build output; readable imports and logic, no malicious patterns. Expected for this UI component library. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.lrswYyKn.js AI (source-diff): Standard Vite minified bundle output; readable imports and component names confirm legitimate build artifact. ai
source-diff obfuscated-file:dist/chunks/AskNetlify.1ejGUA_O.js AI (source-diff): Vite-minified UI component bundle; readable imports and structure confirm legitimate build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/chunks/ChatInterface.BLB99yBP.js AI (source-diff): Vite build output; minified but readable ES module code with clear Preact/component imports, not obfuscated. ai
source-diff obfuscated-file:dist/chunks/ChatInterface.BD7rlv4H.js AI (source-diff): Vite-bundled UI chunk with readable imports; minified but not obfuscated, consistent with build tooling for this package. ai
dependencies unvetted-dep:@kapaai/react-sdk AI (dependencies): Intentional addition for AskNetlify AI chat feature; consistent with new bundle files in this version. ai
dependencies unvetted-dep:vite-plugin-lib-inject-css AI (dependencies): Common Vite library build plugin; consistent with this package's build setup. ai
dependencies unvetted-dep:@preact/preset-vite AI (dependencies): Standard Preact/Vite build tooling; expected for a Preact component library. ai
bogus-package bogus-package AI (bogus-package): Scoped @netlify package with 139 versions and 2.1k downloads; clearly not spam despite missing metadata. ai
phantom-deps phantom-dep:@astro-community/astro-embed-youtube AI (phantom-deps): Astro integration referenced in config; stable false positive. ai
phantom-deps phantom-dep:@shikijs/transformers AI (phantom-deps): Build/syntax-highlighting utility referenced in config only; stable false positive for this package. ai
phantom-deps phantom-dep:vite-tsconfig-paths AI (phantom-deps): Vite plugin referenced in build config only; stable false positive for this package. ai
phantom-deps phantom-dep:@preact/preset-vite AI (phantom-deps): Vite plugin referenced in build config only; stable false positive for this package. ai
phantom-deps phantom-dep:vite-plugin-dts AI (phantom-deps): vite-plugin-dts is a build tool in config files only; stable false positive for this Vite-based library. ai
phantom-deps phantom-dep:glob AI (phantom-deps): glob is a build utility referenced in config/scripts only; stable false positive for this package. ai
phantom-deps phantom-dep:vite AI (phantom-deps): vite is a build tool referenced in config files only; phantom-dep is a stable false positive for this Vite-based component library. ai
phantom-deps phantom-dep:vite-plugin-lib-inject-css AI (phantom-deps): Vite plugin referenced in build config only; stable false positive for this package. ai

Versions (showing 51 of 74)

View all versions
Version Deps Published
1.28.0 8 / 24
1.27.7 8 / 24
1.27.6 8 / 24
1.27.5 8 / 24
1.27.4 8 / 24
1.27.3 8 / 24
1.27.2 8 / 24
1.27.1 8 / 24
1.27.0 8 / 24
1.26.0 8 / 24
1.25.0 4 / 24
1.24.1 4 / 24
1.24.0 11 / 9
1.23.1 11 / 9
1.23.0 11 / 9
1.22.0 11 / 9
1.21.1 10 / 9
1.20.1 10 / 9
1.20.0 10 / 9
1.19.0 10 / 9
1.18.0 10 / 9
1.17.6 10 / 9
1.17.5 10 / 9
1.17.4 10 / 9
1.17.3 10 / 9
1.17.2 10 / 9
1.17.1 10 / 9
1.17.0 10 / 9
1.16.0 10 / 9
1.15.1 10 / 9
1.15.0 10 / 9
1.14.6 10 / 9
1.14.5 10 / 9
1.14.4 10 / 9
1.14.3 10 / 9
1.14.2 10 / 9
1.14.1 10 / 9
1.14.0 10 / 9
1.13.3 10 / 9
1.13.2 10 / 9
1.13.1 10 / 9
1.13.0 10 / 9
1.12.4 10 / 9
1.12.3 10 / 9
1.12.2 10 / 9
1.12.1 10 / 9
1.12.0 10 / 9
1.11.0 10 / 9
1.10.0 10 / 9
1.9.1 10 / 9
1.9.0 10 / 9

v1.28.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.26.0

3 findings
HIGH Publisher changed: akardet → GitHub Actions (on 2026-07-16) provenance

This version was published by a different npm account than previous versions on 2026-07-16. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/chunks/AskNetlify.bx0blyGV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.