← Home

@plumile/ui

Shared React UI primitives and theme for Kronex applications

5
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ohardy

Keywords

reactuivanilla-extractdesign-systemtypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:lib/esm/src-BPX_89p7.js AI (source-diff): Minified Vite bundle of React/vanilla-extract/nivo UI code; readable imports confirm legitimate build output. ai
source-diff obfuscated-file:lib/esm/src-DJ_3P36n.js AI (source-diff): Minified Vite bundle chunk; imports are clearly from react, @vanilla-extract, @nivo/line — all declared dependencies. ai
source-diff obfuscated-file:lib/esm/node_modules/mermaid/dist/chunks/mermaid.core/flowDiagram-I6XJVG4X.js AI (source-diff): Standard minified mermaid.js build artifact from declared mermaid dependency; no malicious indicators. ai
source-diff obfuscated-file:lib/esm/node_modules/mermaid/dist/chunks/mermaid.core/c4Diagram-AAUBKEIU.js AI (source-diff): Standard minified mermaid.js build artifact from declared mermaid dependency; no malicious indicators. ai
source-diff obfuscated-file:lib/esm/flowDiagram-DWJPFMVM-BkxIhdyA.js AI (source-diff): Standard Vite ESM bundle of mermaid flowDiagram chunk; readable code with source map, not malicious obfuscation. ai
source-diff obfuscated-file:lib/esm/src-CUtn9cbu.js AI (source-diff): Standard Vite ESM bundle of UI components; readable React/vanilla-extract code, not malicious obfuscation. ai
phantom-deps phantom-dep:@vanilla-extract/sprinkles AI (phantom-deps): Referenced in config files; consistent with optional UI component library pattern. ai
phantom-deps phantom-dep:@dnd-kit/core AI (phantom-deps): Newly added runtime dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:@dnd-kit/sortable AI (phantom-deps): Newly added runtime dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:@dnd-kit/utilities AI (phantom-deps): Newly added runtime dep referenced in config; stable false positive. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped UI library; no relation to 'pg' postgres client. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): Scoped UI library @plumile/ui; Levenshtein match to 'uuid' is coincidental, not a typosquat. ai
phantom-deps phantom-dep:react-shiki AI (phantom-deps): react-shiki is declared as a dependency and referenced in config; phantom-dep heuristic misfires here. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a known implicit TypeScript runtime dependency; stable false positive. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped UI library; no relation to 'yup'. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped UI library; no relation to 'joi'. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped UI library; no relation to 'qs'. ai
phantom-deps phantom-dep:mermaid AI (phantom-deps): mermaid is declared as a dependency and referenced in config; phantom-dep heuristic misfires here. ai
semgrep semgrep:dll-hijacking-commands AI (semgrep): Fires on frozen JSON TextMate grammar data inside a syntax-highlighter bundle, not actual DLL hijacking commands. ai

Versions (showing 5 of 105)

Version Deps Published
0.1.57 7 / 8
0.1.56 7 / 8
0.1.55 6 / 6
0.1.54 6 / 6
0.1.53 6 / 6

v0.1.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.54

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.