← Home

@powerhousedao/design-system

This repository contains base and scoped (project) components, utilities, and hooks for the powerhouse org.

23
Versions
AGPL-3.0-only
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

acaldas.powerhousememo.devryanwolhuterprometheus-phcallme-tfroidliberuum

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/icon-C4QOpsdI.js AI (source-diff): Bundled SVG icon components; long lines are minified JSX output, not malicious obfuscation. Stable pattern for this design-system package. ai
provenance publisher-changed AI (provenance): New publisher memo.dev has strong track record (75 approved, 0 rejected) and SLSA provenance confirms CI/CD publish. ai
source-diff obfuscated-file:dist/connect/index.js AI (source-diff): Standard ESM bundle output from tsdown/rollup; code is readable React component logic, not obfuscated. ai
source-diff obfuscated-file:dist/src-BgCjYazJ.js AI (source-diff): Standard ESM bundle chunk; sample shows plain readable React component code. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation confirms CI/CD publish; dormancy explained by monorepo cadence, not account takeover indicators. ai
dependencies unvetted-dep:document-drive AI (dependencies): Pinned to same version (5.3.2) as this package; part of coordinated Powerhouse monorepo release. ai
phantom-deps phantom-dep:nanoid AI (phantom-deps): Common utility; phantom detection is a false positive for this design system package. ai
phantom-deps phantom-dep:world-countries AI (phantom-deps): Expected for a design system with country/flag components; phantom detection is a false positive. ai
phantom-deps phantom-dep:focus-trap-react AI (phantom-deps): Expected accessibility dependency for a design system; phantom detection is a false positive. ai
phantom-deps phantom-dep:react-day-picker AI (phantom-deps): Expected date picker dependency for a design system; phantom detection is a false positive. ai
phantom-deps phantom-dep:react-virtualized AI (phantom-deps): Expected virtualization dependency for a design system; phantom detection is a false positive. ai
dependencies unvetted-dep:@radix-ui/react-dialog AI (dependencies): @radix-ui/react-dialog is a widely-used, well-maintained Radix UI primitive; legitimate dependency for a design system. ai
phantom-deps phantom-dep:@radix-ui/react-switch AI (phantom-deps): Radix UI primitive expected in a design system; phantom detection is a false positive. ai
phantom-deps phantom-dep:@internationalized/date AI (phantom-deps): Expected date internationalization dependency for a design system; phantom detection is a false positive. ai
phantom-deps phantom-dep:@radix-ui/react-separator AI (phantom-deps): Radix UI primitive expected in a design system; phantom detection is a false positive. ai
phantom-deps phantom-dep:@powerhousedao/document-engineering AI (phantom-deps): Same-org dependency; phantom detection is a false positive for this design system. ai
phantom-deps phantom-dep:react-circle-flags AI (phantom-deps): Expected for a design system with country/flag components; phantom detection is a false positive. ai
dependencies unvetted-dep:@radix-ui/react-tooltip AI (dependencies): @radix-ui/react-tooltip is a widely-used, well-maintained Radix UI primitive; legitimate dependency for a design system. ai
dependencies unvetted-dep:@radix-ui/react-dropdown-menu AI (dependencies): @radix-ui/react-dropdown-menu is a widely-used, well-maintained Radix UI primitive; legitimate dependency for a design system. ai
dependencies unvetted-dep:@powerhousedao/document-engineering AI (dependencies): Same-org dependency from the Powerhouse DAO organization; expected for this design system package. ai
phantom-deps phantom-dep:tsx AI (phantom-deps): Declared in deps for script usage (create-icon-components script); phantom detection is a false positive for this design system. ai
phantom-deps phantom-dep:viem AI (phantom-deps): Design system with Web3 components; declared but may be used indirectly or in specific component paths not detected by static analysis. ai

Versions (showing 23 of 23)

Version Deps Published
6.1.0 29 / 44
6.0.0 27 / 42
5.3.6 45 / 45
5.3.5 45 / 45
5.3.4 45 / 45
5.3.3 45 / 45
5.3.2 45 / 45
5.3.1 45 / 45
5.3.0 45 / 45
5.1.0 42 / 46
5.0.12 42 / 46
5.0.11 42 / 46
5.0.10 42 / 46
5.0.9 42 / 46
5.0.8 42 / 46
5.0.7 42 / 46
5.0.6 42 / 46
5.0.5 42 / 46
5.0.4 42 / 46
5.0.3 42 / 46
5.0.2 42 / 46
5.0.1 42 / 46
5.0.0 42 / 46

v6.1.0

2 findings
HIGH New obfuscated file: dist/icon-C4QOpsdI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.0

4 findings
HIGH Publisher changed: acaldas.powerhouse → memo.dev (on 2026-05-21) provenance

This version was published by a different npm account than previous versions on 2026-05-21. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/connect/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src-BgCjYazJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.