@pega/cosmos-react-core
Cosmos is a visual design system and UI component collection. Its goal is to empower application developers in their pursuit to create engaging and rewarding user experiences.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Established Pega design system; missing repo/homepage metadata is a packaging style choice, not a spam indicator. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): High-velocity enterprise package with 1280 versions; rapid successive publishes are normal for this project. | ai | |
| phantom-deps | phantom-dep:@types/react-grid-layout | AI (phantom-deps): Type definitions for declared runtime dep; stable pattern. | ai | |
| phantom-deps | phantom-dep:@types/dom-speech-recognition | AI (phantom-deps): Type definitions for declared runtime dep; stable pattern. | ai | |
| phantom-deps | phantom-dep:timezoned-date | AI (phantom-deps): Config-referenced runtime dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:react-resizable | AI (phantom-deps): Config-referenced runtime dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@types/timezoned-date | AI (phantom-deps): Type definitions for declared runtime dep; stable pattern. | ai | |
| phantom-deps | phantom-dep:@types/google.maps | AI (phantom-deps): TypeScript type definitions for declared runtime dep; stable pattern. | ai | |
| phantom-deps | phantom-dep:@types/emoji-mart | AI (phantom-deps): TypeScript type definitions for declared runtime dep; stable pattern. | ai | |
| phantom-deps | phantom-dep:@types/emoji-regex | AI (phantom-deps): TypeScript type definitions for declared runtime dep; stable pattern. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Framework-scoped types; stable pattern for React libraries. | ai | |
| phantom-deps | phantom-dep:@types/styled-components | AI (phantom-deps): Type package for declared dependency; stable pattern. | ai | |
| phantom-deps | phantom-dep:@types/dompurify | AI (phantom-deps): Type package for declared dependency; stable pattern. | ai | |
| phantom-deps | phantom-dep:@types/qrcode | AI (phantom-deps): Type package for declared dependency; stable pattern. | ai | |
| phantom-deps | phantom-dep:@types/react-dom | AI (phantom-deps): Framework-scoped types; stable pattern for React libraries. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 8.21.7 | 31 / 6 | |
| 8.21.6 | 31 / 6 | |
| 8.21.5 | 31 / 6 | |
| 8.21.4 | 31 / 6 | |
| 8.21.3 | 31 / 6 | |
| 8.21.2 | 31 / 6 | |
| 8.21.1 | 31 / 6 | |
| 8.21.0 | 31 / 6 | |
| 8.20.0 | 31 / 6 | |
| 8.19.0 | 31 / 6 | |
| 8.18.3 | 31 / 6 | |
| 8.18.2 | 31 / 6 | |
| 8.18.1 | 31 / 6 | |
| 8.18.0 | 31 / 6 | |
| 8.17.2 | 31 / 6 | |
| 8.17.1 | 31 / 6 | |
| 8.17.0 | 31 / 6 | |
| 8.16.1 | 31 / 6 | |
| 8.16.0 | 31 / 6 | |
| 7.17.0 | 27 / 6 | |
| 7.16.5 | 27 / 6 | |
| 7.16.4 | 27 / 6 | |
| 7.16.3 | 27 / 6 | |
| 7.16.2 | 27 / 6 | |
| 7.16.1 | 27 / 6 | |
| 7.16.0 | 27 / 6 | |
| 6.6.3 | 22 / 5 |
v8.21.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.21.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.21.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.21.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.21.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.21.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.21.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.20.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.19.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.18.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.18.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.18.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.18.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.17.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.17.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.17.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.16.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.16.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.16.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.16.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.16.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.16.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.16.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.6.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.