@react-email/ui
A live preview of your emails right in your browser.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:.next/static/chunks/08l40kl5rf2s2.js | AI (source-diff): Bundled Next.js client chunk (socket.io/server actions); no hostile destination. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0nvn3s74q.6bx.js | AI (source-diff): Turbopack-minified Next.js build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/08l40kl5rf2s2.js | AI (source-diff): Turbopack-minified Next.js build output, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Ships prebuilt .next/ Next.js output; large file count is expected build artifact. | ai | |
| source-diff | net-exec-file:.next/server/chunks/ssr/[root-of-the-server]__0jx5d~g._.js | AI (source-diff): Next.js SSR framework chunk; net+exec is bundled framework runtime, not a dropper. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0lr09bmu7rmb7.js | AI (source-diff): Turbopack chunk (socket.io/server-reference code); bundled build output, not malicious obfuscation. | ai | |
| source-diff | net-exec-file:.next/static/chunks/0lr09bmu7rmb7.js | AI (source-diff): Network+exec patterns are socket.io-client and Next runtime in bundled chunk; no hostile destination. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0~7l~osi-vib3.js | AI (source-diff): Next.js Turbopack build output; minified bundle, not obfuscation. Stable for this package's .next artifacts. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0m9mgk0vsiw9p.js | AI (source-diff): Next.js Turbopack minified build chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0u~_~je~n_70n.js | AI (source-diff): Turbopack build chunk with socket.io/server-reference code. | ai | |
| source-diff | net-exec-file:.next/static/chunks/0u~_~je~n_70n.js | AI (source-diff): Framework runtime (socket.io + server references), not a dropper. | ai | |
| source-diff | obfuscated-file:.next/server/chunks/ssr/03fj_@react-email_render_dist_node_index_mjs_07s9qau._.js | AI (source-diff): Bundled framework build output; benign. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/15~.oo6-h3ou6.js | AI (source-diff): Turbopack static chunk; minified build output. | ai | |
| source-diff | obfuscated-file:.next/server/chunks/ssr/[root-of-the-server]__1053b3h._.js | AI (source-diff): Next.js Turbopack SSR bundle, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0ikq9jgw.1_-v.js | AI (source-diff): Turbopack static chunk; minified build output. | ai | |
| publish-pattern | suspicious-version-number | AI (publish-pattern): 6.6.6 is the real monorepo release train version, not malicious signaling. | ai | |
| source-diff | net-exec-file:.next/static/chunks/15~.oo6-h3ou6.js | AI (source-diff): Framework runtime (socket.io/server-reference) in bundled Next output; no hostile target. | ai | |
| source-diff | net-exec-file:.next/static/chunks/0hx-75qyl6ejs.js | AI (source-diff): Next.js runtime chunk with socket.io client; expected for this preview server package. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0hx-75qyl6ejs.js | AI (source-diff): Turbopack-bundled Next.js chunk; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/11_bnx49.ejco.js | AI (source-diff): Turbopack-bundled Next.js chunk; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:.next/static/chunks/185zrzqsa5ioh.js | AI (source-diff): Socket.io client + server references bundled by Turbopack; expected for this package. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0n14b0i3_84-~.js | AI (source-diff): Next.js Turbopack bundled output, not obfuscation; stable for this package. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/185zrzqsa5ioh.js | AI (source-diff): Next.js Turbopack bundled output, not obfuscation; stable for this package. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0sisxbmenq4hx.js | AI (source-diff): Standard Next.js Turbopack minified chunk; expected for pre-built .next output. | ai | |
| source-diff | net-exec-file:.next/static/chunks/0sisxbmenq4hx.js | AI (source-diff): Next.js runtime includes WebSocket + dynamic loading; not malicious. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0jj.99uuyrq-6.js | AI (source-diff): Standard Next.js Turbopack minified chunk; expected for pre-built .next output. | ai | |
| source-diff | net-exec-file:.next/static/chunks/0c0l8r.k9y4rn.js | AI (source-diff): Next.js client chunk with socket.io and Blob handling; not malicious. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0c0l8r.k9y4rn.js | AI (source-diff): Standard Turbopack minified chunk from Next.js build output. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/11otrz2g_0hv0.js | AI (source-diff): Standard Turbopack minified chunk from Next.js build output. | ai | |
| source-diff | net-exec-file:.next/static/chunks/18bju6jqw_f3j.js | AI (source-diff): Bundled socket.io + server references in Next.js chunk; expected for this package. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0~_0fpd4p.o84.js | AI (source-diff): Standard Turbopack minified chunk from Next.js build output. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/18bju6jqw_f3j.js | AI (source-diff): Standard Turbopack minified chunk from Next.js build output. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/07xz95h5_vkz5.js | AI (source-diff): Next.js Turbopack client chunk; standard build artifact. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/05gb77d41e6_j.js | AI (source-diff): Next.js Turbopack client chunk; standard build artifact. | ai | |
| source-diff | obfuscated-file:.next/server/chunks/ssr/[root-of-the-server]__0kj8k7~._.js | AI (source-diff): Next.js Turbopack SSR build output; expected for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Well-known package from resend org; low score is noise. | ai | |
| semgrep | semgrep:etc-passwd-access | AI (semgrep): Test file asserting path-traversal is blocked; not credential harvesting. | ai | |
| source-diff | net-exec-file:.next/static/chunks/07xz95h5_vkz5.js | AI (source-diff): Socket.io client + Next.js runtime bundled together; not malicious. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/07109i_ivtgcv.js | AI (source-diff): Turbopack static chunk (clsx + tailwind-merge); standard minified build output. | ai | |
| source-diff | net-exec-file:.next/server/chunks/ssr/[root-of-the-server]__0o1z5so._.js | AI (source-diff): Babel parser + file-system traversal in SSR chunk; no exfiltration or dropper pattern, legitimate Next.js build output. | ai | |
| source-diff | obfuscated-file:.next/server/chunks/ssr/[root-of-the-server]__0o1z5so._.js | AI (source-diff): Standard Next.js SSR chunk containing Babel parser; expected minification for this package. | ai | |
| source-diff | obfuscated-file:.next/server/chunks/ssr/[root-of-the-server]__0ijmwvt._.js | AI (source-diff): Standard Next.js/Turbopack SSR build artifact containing prettier/deepmerge; expected minification. | ai | |
| source-diff | obfuscated-file:.next/server/chunks/ssr/[root-of-the-server]__08ttim4._.js | AI (source-diff): Standard Next.js/Turbopack SSR build artifact; minification is expected for this package. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/15xwcf8r22gq-.js | AI (source-diff): Standard Next.js static chunk; expected minification for this package. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0z8xesoucltu7.js | AI (source-diff): Standard Next.js static chunk; expected minification for this package. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0wdedq5_rk8gw.js | AI (source-diff): Turbopack static chunk (Next.js utils); standard minified build output. | ai | |
| source-diff | net-exec-file:.next/static/chunks/0uh-49~tky78v.js | AI (source-diff): Socket.io-client WebSocket code in a static chunk; no dropper pattern, legitimate Next.js build output. | ai | |
| source-diff | obfuscated-file:.next/static/chunks/0uh-49~tky78v.js | AI (source-diff): Turbopack static chunk (socket.io-client + Next.js server actions); expected minification. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): esbuild binary is a declared runtime dependency; expected for this Next.js-based UI package. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped @react-email package; Levenshtein match to pg is a false positive. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Fires in bundled Next.js HMR chunk reading env for config; standard framework behavior. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Fires in bundled Next.js HMR/dev-server chunk; expected for a Next.js app bundle. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Fires in Turbopack runtime chunk-loading code; expected Next.js internals. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Fires inside bundled Next.js server chunks; standard framework code. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Fires inside bundled Next.js server chunks; standard framework code, not malicious. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @react-email package; Levenshtein match to yup is a false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @react-email package; Levenshtein match to joi is a false positive. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped @react-email package; Levenshtein match to qs is a false positive. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped @react-email package; Levenshtein match to uuid is a false positive. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 6.8.1 | 2 / 53 | |
| 6.8.0 | 2 / 53 | |
| 6.7.0 | 2 / 53 | |
| 6.6.8 | 2 / 53 | |
| 6.6.6 | 2 / 53 | |
| 6.6.5 | 2 / 53 | |
| 6.6.4 | 2 / 51 | |
| 6.6.3 | 2 / 51 | |
| 6.6.2 | 2 / 51 | |
| 6.6.0 | 2 / 51 | |
| 6.3.3 | 2 / 51 | |
| 6.3.0 | 2 / 51 | |
| 6.1.5 | 2 / 51 | |
| 6.0.5 | 2 / 51 | |
| 6.0.4 | 2 / 51 | |
| 6.0.3 | 2 / 51 | |
| 6.0.2 | 2 / 51 | |
| 6.0.1 | 2 / 51 | |
| 6.0.0 | 2 / 51 |
v6.8.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.8.0
37 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.7.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.8
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.6
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.5
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.