@preply/ds-web-lib
11
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
preply-admineugenegodunerebus1alex.semeniukit-serviceserhii.tonkoshkurlukas-preplychinskiy_preply
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Preply internal design system package; provenance not configured in their CI pipeline across all versions. | ai | |
| dependencies | unvetted-dep:@base-ui-components/react | AI (dependencies): Known MUI/Base UI project; beta version constraint is intentional for this design-system package. | ai | |
| phantom-deps | phantom-dep:react-is | AI (phantom-deps): Declared in deps and @types in devDeps; used indirectly via config/barrel pattern. | ai | |
| phantom-deps | phantom-dep:@react-aria/focus | AI (phantom-deps): Component library dependency; phantom-dep heuristic unreliable for bundled libs. | ai | |
| phantom-deps | phantom-dep:usehooks-ts | AI (phantom-deps): Component library dependency; phantom-dep heuristic unreliable for bundled libs. | ai | |
| phantom-deps | phantom-dep:sonner | AI (phantom-deps): Component library likely re-exports or uses in config; stable false positive for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped internal design-system library; missing metadata is expected for org-internal packages. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Internal scoped package; missing description is consistent across all versions. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 14.2.0 | 5 / 19 | |
| 11.5.0 | 5 / 19 | |
| 11.4.0 | 5 / 19 | |
| 11.3.0 | 5 / 19 | |
| 11.2.0 | 5 / 19 | |
| 8.0.0 | 6 / 19 | |
| 7.1.0 | 6 / 19 | |
| 6.2.1 | 6 / 19 | |
| 6.2.0 | 6 / 19 | |
| 6.1.0 | 6 / 19 | |
| 6.0.0 | 6 / 19 |
v14.2.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.