@ovhcloud/ods-react
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/FileUploadList-DAdlu9VZ.js | AI (source-diff): Bundled Vite chunk with clear imports/logic, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/FileUploadList-DgswBlX6.js | AI (source-diff): Vite-bundled minified chunk, not obfuscation; no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/phone-number-9goO13qW.js | AI (source-diff): Minified libphonenumber data bundle, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected growth from new component set (FileUpload, phone input, datepicker, code viewer). | ai | |
| source-diff | obfuscated-file:dist/chunks/icon-name-Dw8X1wVO.js | AI (source-diff): Standard Vite/Rollup CSS module map for icon names; long lines are icon name mappings, not obfuscation. | ai | |
| provenance | no-provenance | AI (provenance): OVHcloud ODS packages consistently lack Sigstore provenance; stable false positive for this publisher. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 19.7.3 | 11 / 27 | |
| 19.7.2 | 11 / 27 | |
| 19.7.1 | 10 / 24 | |
| 19.7.0 | 10 / 24 | |
| 19.6.1 | 6 / 24 | |
| 19.6.0 | 6 / 24 | |
| 19.5.0 | 5 / 24 | |
| 19.4.1 | 5 / 24 | |
| 19.4.0 | 5 / 24 | |
| 19.3.0 | 5 / 24 | |
| 19.2.1 | 3 / 23 | |
| 19.2.0 | 3 / 23 | |
| 19.1.0 | 3 / 23 | |
| 19.0.1 | 3 / 23 | |
| 19.0.0 | 3 / 23 |
v19.6.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v19.6.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.