← Home

@planningcenter/tapestry-react

39
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

jonsuhkeolakylemellandertimmorgandanott

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): Intra-org dependency swap for design tokens, not a third-party addition. ai
source-diff obfuscated-file:dist/packages/tokens-shim/dist/index.js AI (source-diff): Minified design-token constants object, not obfuscated/malicious code. ai
provenance no-provenance AI (provenance): Internal org package; provenance not part of their publish workflow across 173 versions. ai
phantom-deps phantom-dep:match-sorter AI (phantom-deps): Likely re-exported or used indirectly; stable pattern for this component library. ai
phantom-deps phantom-dep:@planningcenter/icons AI (phantom-deps): Same org scope; phantom-dep heuristic false positive. ai
dependencies unvetted-dep:tiny-spring AI (dependencies): Small animation utility; no known malicious history, stable dep for this package. ai
dependencies unvetted-dep:@planningcenter/react-beautiful-dnd AI (dependencies): Same org fork of react-beautiful-dnd; internal dependency, not a third-party risk. ai
dependencies unvetted-dep:focus-options-polyfill AI (dependencies): Well-known accessibility polyfill; no malicious history. ai
dependencies unvetted-dep:@planningcenter/icons AI (dependencies): Same org scope; internal dependency, not a third-party risk. ai
license uncommon-license:UNLICENSED AI (license): Intentionally proprietary; consistent across all 173 versions of this org package. ai
bogus-package bogus-package AI (bogus-package): Internal org component library; sparse README and no keywords are expected for a private/scoped package. ai
phantom-deps phantom-dep:mitt AI (phantom-deps): Large UI component library; deps referenced in config/re-exports are a stable pattern. ai
phantom-deps phantom-dep:popper-max-size-modifier AI (phantom-deps): Same as above; stable false positive for this package. ai
phantom-deps phantom-dep:@planningcenter/tapestry AI (phantom-deps): Same-org sibling dep; stable false positive. ai
phantom-deps phantom-dep:@react-hook/window-size AI (phantom-deps): Same as above; stable false positive for this package. ai
phantom-deps phantom-dep:@popmotion/popcorn AI (phantom-deps): Same as above; stable false positive for this package. ai
phantom-deps phantom-dep:react-sticky-box AI (phantom-deps): Same as above; stable false positive for this package. ai
phantom-deps phantom-dep:tiny-spring AI (phantom-deps): Same as above; stable false positive for this package. ai
phantom-deps phantom-dep:mousetrap AI (phantom-deps): Same as above; stable false positive for this package. ai
phantom-deps phantom-dep:polished AI (phantom-deps): Same as above; stable false positive for this package. ai
phantom-deps phantom-dep:date-fns AI (phantom-deps): Same as above; stable false positive for this package. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): Same as above; stable false positive for this package. ai

Versions (showing 39 of 39)

Version Deps Published
5.1.1 20 / 33
5.0.0 20 / 33
4.15.0 20 / 33
4.14.4 20 / 33
4.14.3 20 / 33
4.14.2 20 / 33
4.14.1 20 / 33
4.14.0 20 / 33
4.13.2 20 / 33
4.13.1 20 / 33
4.13.0 20 / 33
4.12.3 20 / 32
4.12.2 20 / 32
4.12.1 20 / 32
4.12.0 20 / 32
4.11.5 20 / 32
4.11.4 20 / 32
4.11.3 20 / 32
4.11.2 20 / 32
4.11.1 20 / 32
4.11.0 20 / 32
4.10.2 20 / 32
4.10.1 20 / 32
4.10.0 20 / 39
4.9.0 20 / 39
4.8.0 20 / 39
4.7.2 20 / 39
4.7.1 20 / 39
4.7.0 20 / 39
4.6.3 20 / 37
4.6.2 20 / 37
4.6.1 20 / 38
4.6.0 20 / 38
4.5.1 20 / 38
4.5.0 20 / 38
4.4.1 20 / 38
4.4.0 20 / 38
4.3.3 20 / 38
4.3.2 20 / 38

v5.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.11.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.10.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.10.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.10.0

2 findings
HIGH New obfuscated file: dist/packages/tokens-shim/dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.0

2 findings
HIGH New obfuscated file: dist/packages/tokens-shim/dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.8.0

2 findings
HIGH New obfuscated file: dist/packages/tokens-shim/dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.2

2 findings
HIGH New obfuscated file: dist/packages/tokens-shim/dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.1

2 findings
HIGH New obfuscated file: dist/packages/tokens-shim/dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.0

2 findings
HIGH New obfuscated file: dist/packages/tokens-shim/dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.