@salt-ds/core
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-tripled | AI (source-diff): New deps + generated CSS.js files explain size growth; no malicious content found. | ai | |
| source-diff | obfuscated-file:dist-es/packages/core/src/card/InteractableCard.css.js | AI (source-diff): style-inject CSS string, long line not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist-cjs/packages/core/src/card/InteractableCard.css.js | AI (source-diff): style-inject CSS string, long line not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist-es/packages/core/src/radio-button/RadioButtonIcon.css.js | AI (source-diff): style-inject CSS string, long line not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist-cjs/packages/core/src/radio-button/RadioButtonIcon.css.js | AI (source-diff): style-inject CSS string, long line not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist-es/packages/core/src/checkbox/CheckboxIcon.css.js | AI (source-diff): style-inject CSS string, long line not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist-cjs/packages/core/src/checkbox/CheckboxIcon.css.js | AI (source-diff): style-inject CSS string, long line not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist-es/packages/core/src/tooltip/Tooltip.css.js | AI (source-diff): Same CSS-in-JS pattern, ES build variant. | ai | |
| source-diff | obfuscated-file:dist-cjs/packages/core/src/tooltip/Tooltip.css.js | AI (source-diff): Long-line CSS string literal, not obfuscated code; standard css-in-js build pattern. | ai | |
| source-diff | obfuscated-file:dist-es/card/InteractableCard.css.js | AI (source-diff): CSS-in-JS string, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-es/multiline-input/MultilineInput.css.js | AI (source-diff): CSS-in-JS string, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-cjs/multiline-input/MultilineInput.css.js | AI (source-diff): CSS-in-JS string, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-cjs/card/InteractableCard.css.js | AI (source-diff): CSS-in-JS string, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-es/text/Text.css.js | AI (source-diff): CSS-in-JS string, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-cjs/text/Text.css.js | AI (source-diff): CSS-in-JS string, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-es/button/Button.css.js | AI (source-diff): CSS-in-JS string, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-cjs/button/Button.css.js | AI (source-diff): CSS-in-JS string, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-es/input/Input.css.js | AI (source-diff): CSS-in-JS string, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-cjs/input/Input.css.js | AI (source-diff): CSS-in-JS string, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-es/slider/internal/SliderTrack.css.js | AI (source-diff): Long-line CSS string bundle, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-cjs/slider/internal/SliderTrack.css.js | AI (source-diff): Long-line CSS string bundle, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-es/tag/Tag.css.js | AI (source-diff): Same CSS-in-JS pattern as CJS counterpart, benign. | ai | |
| source-diff | obfuscated-file:dist-cjs/tag/Tag.css.js | AI (source-diff): Long-line CSS string bundled as JS module, not code obfuscation. | ai | |
| source-diff | obfuscated-file:dist-cjs/packages/core/src/card/Card.css.js | AI (source-diff): CSS string bundled as single long line via style-inject; build artifact, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist-es/packages/core/src/card/Card.css.js | AI (source-diff): Same CSS-in-JS bundling pattern in ESM build output. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New component (SidePanel) build output; consistent with monorepo release pattern. | ai | |
| source-diff | obfuscated-file:dist-es/tree/TreeNodeTrigger.css.js | AI (source-diff): CSS-in-JS bundle pattern; long lines are CSS strings, not obfuscated code. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist-cjs/tree/TreeNodeTrigger.css.js | AI (source-diff): CSS-in-JS bundle pattern; long lines are CSS strings, not obfuscated code. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist-cjs/side-panel/SidePanel.css.js | AI (source-diff): CSS-in-JS bundle pattern; readable CSS string inlined as JS variable, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-es/side-panel/SidePanel.css.js | AI (source-diff): CSS-in-JS bundle pattern; readable CSS string inlined as JS variable, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist-es/vertical-navigation/VerticalNavigationItemContent.css.js | AI (source-diff): CSS-in-JS build artifact; long lines are inlined CSS strings, not obfuscation. Stable pattern for this design system package. | ai | |
| source-diff | obfuscated-file:dist-cjs/vertical-navigation/VerticalNavigationItemContent.css.js | AI (source-diff): CSS-in-JS build artifact; long lines are inlined CSS strings, not obfuscation. Stable pattern for this design system package. | ai | |
| source-diff | obfuscated-file:dist-es/number-input/NumberInput.css.js | AI (source-diff): CSS-in-JS bundle with readable CSS content; standard build artifact for this design system package. | ai | |
| source-diff | obfuscated-file:dist-es/table/Table.css.js | AI (source-diff): CSS-in-JS bundle with readable CSS content; standard build artifact for this design system package. | ai | |
| source-diff | obfuscated-file:dist-cjs/table/Table.css.js | AI (source-diff): CSS-in-JS bundle with readable CSS content; standard build artifact for this design system package. | ai | |
| source-diff | obfuscated-file:dist-cjs/number-input/NumberInput.css.js | AI (source-diff): CSS-in-JS bundle with readable CSS content; standard build artifact for this design system package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): tabbable and dom-accessibility-api are established accessibility libs; appropriate additions for a UI component library. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Monorepo package with legitimate repo; missing description is metadata quirk, not malware indicator. | ai | |
| dependencies | unvetted-dep:@salt-ds/styles | AI (dependencies): Same-monorepo sibling package from jpmorganchase/salt-ds; stable false positive. | ai | |
| dependencies | unvetted-dep:@salt-ds/window | AI (dependencies): Same-monorepo sibling package from jpmorganchase/salt-ds; stable false positive. | ai | |
| dependencies | unvetted-dep:@salt-ds/icons | AI (dependencies): Same-monorepo sibling package from jpmorganchase/salt-ds; stable false positive. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established monorepo package with 340 versions and SLSA provenance; sparse README metadata is not indicative of spam. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @salt-ds/core is a JPMorganChase design system component, not a typosquat of 'cors'. | ai |
Versions (showing 51 of 80)
| Version | Deps | Published |
|---|---|---|
| 1.68.0 | 9 / 2 | |
| 1.67.1 | 9 / 2 | |
| 1.67.0 | 9 / 2 | |
| 1.66.0 | 9 / 2 | |
| 1.65.1 | 9 / 2 | |
| 1.65.0 | 8 / 2 | |
| 1.64.1 | 8 / 2 | |
| 1.64.0 | 8 / 2 | |
| 1.63.0 | 8 / 2 | |
| 1.62.0 | 8 / 2 | |
| 1.61.0 | 8 / 2 | |
| 1.60.0 | 6 / 2 | |
| 1.59.1 | 6 / 2 | |
| 1.59.0 | 6 / 2 | |
| 1.58.0 | 6 / 2 | |
| 1.57.1 | 6 / 2 | |
| 1.57.0 | 6 / 2 | |
| 1.56.0 | 6 / 2 | |
| 1.55.0 | 6 / 2 | |
| 1.54.2 | 6 / 2 | |
| 1.54.1 | 6 / 0 | |
| 1.54.0 | 6 / 0 | |
| 1.53.0 | 6 / 0 | |
| 1.52.1 | 6 / 0 | |
| 1.52.0 | 6 / 0 | |
| 1.51.0 | 6 / 0 | |
| 1.50.0 | 6 / 0 | |
| 1.49.0 | 6 / 0 | |
| 1.48.0 | 5 / 0 | |
| 1.47.5 | 5 / 0 | |
| 1.47.4 | 5 / 0 | |
| 1.47.3 | 5 / 0 | |
| 1.47.2 | 5 / 0 | |
| 1.47.1 | 5 / 0 | |
| 1.47.0 | 5 / 0 | |
| 1.46.1 | 5 / 0 | |
| 1.46.0 | 5 / 0 | |
| 1.45.0 | 5 / 0 | |
| 1.44.1 | 5 / 0 | |
| 1.44.0 | 5 / 0 | |
| 1.43.0 | 5 / 0 | |
| 1.42.0 | 5 / 0 | |
| 1.41.0 | 5 / 0 | |
| 1.40.0 | 5 / 0 | |
| 1.39.0 | 5 / 0 | |
| 1.38.0 | 5 / 0 | |
| 1.37.3 | 5 / 0 | |
| 1.37.2 | 5 / 0 | |
| 1.37.1 | 5 / 0 | |
| 1.37.0 | 5 / 0 | |
| 1.36.0 | 5 / 0 |
v1.68.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.67.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.67.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.44.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.44.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.43.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.42.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.41.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.40.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.39.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.38.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.37.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.37.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.37.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.37.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.36.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.