@pega/cosmos-react-build
8
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
bob-difronzocpmotionssowersbyricmarspega-cosmos
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): @dagrejs/dagre is a well-known graph library replacing dagre; routine dependency migration. | ai | |
| source-diff | source-size-tripled | AI (source-diff): v8→v9 major bump with new components explains size growth; not indicative of injected payload. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Major version release; new component files are expected for this established Pega UI library. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI release pipeline for a large monorepo; rapid publishes are normal for this package family. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped enterprise package from Pegasystems; missing metadata fields are intentional, not spam indicators. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Intentional for this scoped Pegasystems build package; stable across versions. | ai | |
| phantom-deps | phantom-dep:dagre | AI (phantom-deps): Build tooling package; dagre is a peer/config dependency, not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): @types/* packages are type-only, loaded by convention — stable false positive for this build package. | ai | |
| phantom-deps | phantom-dep:@types/dagre | AI (phantom-deps): @types/* packages are type-only, loaded by convention — stable false positive for this build package. | ai | |
| phantom-deps | phantom-dep:@types/react-dom | AI (phantom-deps): @types/* packages are type-only, loaded by convention — stable false positive for this build package. | ai | |
| phantom-deps | phantom-dep:@types/styled-components | AI (phantom-deps): @types/* packages are type-only, loaded by convention — stable false positive for this build package. | ai | |
| phantom-deps | phantom-dep:@types/codemirror | AI (phantom-deps): @types/* packages are type-only, loaded by convention — stable false positive for this build package. | ai | |
| phantom-deps | phantom-dep:tinymce | AI (phantom-deps): tinymce is a declared runtime dep used in RTE component; phantom-dep heuristic misfires on build aggregator packages. | ai | |
| phantom-deps | phantom-dep:@pega/cosmos-react-dnd | AI (phantom-deps): Same-org dep re-exported by this build aggregator; phantom-dep heuristic misfires here. | ai |