@pisell/materials
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:lucide-react | AI (phantom-deps): lucide-react is a declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| source-diff | obfuscated-file:build/lowcode/render/default/async/view.js | AI (source-diff): Identical webpack bundle pattern; minified build artifact, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:build/lowcode/async/view.js | AI (source-diff): Standard webpack bundle output; readable AWS SDK serialization code, not obfuscation. | ai | |
| provenance | missing-githead | AI (provenance): Mature, high-volume package with known maintainer; missing gitHead is a CI environment change, not a malware signal. | ai | |
| source-diff | obfuscated-file:es/components/PisellContactBrief/components/ContactFormModal.js | AI (source-diff): Standard Babel/regenerator transpiled output; not malicious obfuscation for this component library. | ai | |
| source-diff | obfuscated-file:es/components/PisellCards/components/GraphicTextCard/GraphicTextCard.stories.js | AI (source-diff): Standard Babel/regenerator transpiled output; not malicious obfuscation for this component library. | ai | |
| source-diff | obfuscated-file:es/components/hardwareErrorTip/demo.js | AI (source-diff): Babel/regenerator-runtime transpiler output, not obfuscation; stable for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All three new deps are established React ecosystem packages; no malware indicators. | ai | |
| source-diff | obfuscated-file:build/lowcode/render/default/1.js | AI (source-diff): Standard webpack bundle output (webpackJsonpBaseMaterials); minified build artifact, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:build/lowcode/3.js | AI (source-diff): Standard webpack bundle output (webpackJsonpBaseMaterials); minified build artifact, not malicious obfuscation. | ai | |
| provenance | no-provenance | AI (provenance): Provenance attestation is a best-practice recommendation, not a security blocker for established packages. | ai | |
| source-diff | obfuscated-file:es/components/pisellToast/squareToast/renderImperatively.js | AI (source-diff): Babel-transpiled output (regenerator-runtime); standard build artifact, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Active UI component library with 1644 versions; incremental source file additions are expected and consistent with its release history. | ai | |
| source-diff | obfuscated-file:es/components/dataSourceComponents/dataSourceForm/urlUtils.js | AI (source-diff): File is Babel-transpiled ES module output (contains regenerator-runtime MIT header, @babel/helpers patterns). Long lines are a build artifact, not obfuscation. This package ships compiled ES modules as its distribution format. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established internal component library (1627 versions); minimal metadata is consistent with organizational tooling, not spam. | ai | |
| source-diff | obfuscated-file:es/components/pisellRecordBoard/shellFrame/Calendar/BookingCalendar.js | AI (source-diff): File contains standard Babel-transpiled ES5 output (canonical helpers: _typeof, _objectSpread, _regeneratorRuntime). Long lines are minified compiled output, not malicious obfuscation. Normal for a React component library shipping compiled artifacts. | ai | |
| source-diff | obfuscated-file:es/components/pisellRecordBoard/shellFrame/Calendar/BookingCalendarDemo.js | AI (source-diff): File contains standard Babel-transpiled/bundled React component output with recognizable helpers (regeneratorRuntime, _typeof). Long lines are from bundling, not intentional obfuscation. Consistent with this UI component library's build pattern. | ai | |
| dependencies | unvetted-dep:@react-spring/web | AI (dependencies): @react-spring/web is a well-known, widely-used React animation library. Its use in a UI component library is expected and benign. | ai | |
| phantom-deps | phantom-dep:antd-mobile | AI (phantom-deps): antd-mobile is a legitimate declared dependency referenced in config files; phantom-dep finding is a packaging style issue, not a security concern. | ai |
Versions (showing 51 of 275)
| Version | Deps | Published |
|---|---|---|
| 6.12.16 | 30 / 42 | |
| 6.12.15 | 30 / 42 | |
| 6.12.14 | 30 / 42 | |
| 6.12.13 | 30 / 42 | |
| 6.12.12 | 30 / 42 | |
| 6.12.11 | 30 / 42 | |
| 6.12.10 | 30 / 42 | |
| 6.12.9 | 30 / 42 | |
| 6.12.8 | 30 / 42 | |
| 6.12.7 | 30 / 42 | |
| 6.12.5 | 30 / 45 | |
| 6.12.4 | 30 / 45 | |
| 6.12.3 | 30 / 45 | |
| 6.12.1 | 30 / 45 | |
| 6.12.0 | 30 / 45 | |
| 6.11.246 | 30 / 42 | |
| 6.11.245 | 30 / 42 | |
| 6.11.244 | 30 / 42 | |
| 6.11.243 | 30 / 42 | |
| 6.11.242 | 30 / 42 | |
| 6.11.241 | 30 / 42 | |
| 6.11.240 | 30 / 42 | |
| 6.11.239 | 30 / 42 | |
| 6.11.238 | 30 / 42 | |
| 6.11.237 | 30 / 42 | |
| 6.11.236 | 30 / 42 | |
| 6.11.235 | 30 / 42 | |
| 6.11.234 | 30 / 42 | |
| 6.11.233 | 30 / 42 | |
| 6.11.232 | 30 / 42 | |
| 6.11.231 | 30 / 42 | |
| 6.11.230 | 30 / 42 | |
| 6.11.229 | 30 / 42 | |
| 6.11.228 | 30 / 42 | |
| 6.11.227 | 30 / 42 | |
| 6.11.226 | 30 / 45 | |
| 6.11.225 | 30 / 45 | |
| 6.11.224 | 30 / 45 | |
| 6.11.223 | 30 / 45 | |
| 6.11.222 | 30 / 45 | |
| 6.11.221 | 30 / 45 | |
| 6.11.220 | 30 / 45 | |
| 6.11.219 | 30 / 45 | |
| 6.11.218 | 30 / 45 | |
| 6.11.217 | 30 / 45 | |
| 6.11.216 | 30 / 45 | |
| 6.11.215 | 30 / 45 | |
| 6.11.214 | 30 / 45 | |
| 6.11.213 | 30 / 45 | |
| 6.11.212 | 30 / 45 | |
| 6.11.211 | 30 / 45 |
v6.12.16
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (ah-sc) on 2026-07-27, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.12.15
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.
v6.12.14
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (jinglin.tan) on 2026-07-20, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.12.13
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zhiwei.wang) on 2026-07-18, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.12.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.12.11
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (ah-sc) on 2026-07-17, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.12.10
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ah-sc) than the most recent previously approved version (jinglin.tan) on 2026-07-16, but ah-sc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.12.9
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (jinglin.tan) on 2026-07-16, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.12.8
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (jinglin.tan) on 2026-07-07, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.12.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.12.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.12.4
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (jinglin.tan) on 2026-06-29, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.12.3
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-06-27, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.11.246
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ah-sc.
This version was published by a different npm account (ah-sc) than the most recent previously approved version (jinglin.tan) on 2026-07-27, but ah-sc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.11.245
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.
v6.11.244
3 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.
This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (jinglin.tan) on 2026-07-25, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.11.243
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.
v6.11.242
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.
v6.11.241
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.
v6.11.240
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.239
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.238
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zhiwei.wang) on 2026-07-21, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.11.237
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zhiwei.wang) on 2026-07-14, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.11.236
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.235
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wang_han) than the most recent previously approved version (zhiwei.wang) on 2026-07-13, but wang_han is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.11.234
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.233
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.232
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.231
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.230
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (xiangfeng.xue) on 2026-07-10, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.11.229
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.
v6.11.228
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.
v6.11.227
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.
v6.11.226
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.11.225
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ah-sc) than the most recent previously approved version (jinglin.tan) on 2026-06-29, but ah-sc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.