@salutejs/plasma-b2c
Salute Design System / React UI kit for business-related web applications.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/DatePicker/DatePicker.config.js | AI (source-diff): Babel-compiled styled-components template, not obfuscation. | ai | |
| source-diff | obfuscated-file:es/components/DatePicker/DatePicker.config.js | AI (source-diff): Babel-compiled styled-components template, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/Slider/Slider.config.js | AI (source-diff): Long-line CSS template literal from Babel build, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/Range/Range.config.js | AI (source-diff): Long-line CSS template literal from Babel build, not obfuscation. | ai | |
| source-diff | obfuscated-file:es/components/Range/Range.config.js | AI (source-diff): Same benign long-line CSS template literal, ESM build. | ai | |
| source-diff | obfuscated-file:es/components/Slider/Slider.config.js | AI (source-diff): Same benign long-line CSS template literal, ESM build. | ai | |
| source-diff | obfuscated-file:dist/styled-components/cjs/components/Attach/Attach.config.js | AI (source-diff): Minified SWC build output from styled-components build script, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/styled-components/cjs/components/Autocomplete/Autocomplete.config.js | AI (source-diff): Minified SWC build output from styled-components build script, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/Autocomplete/Autocomplete.config.js | AI (source-diff): Same SWC-compiled config pattern, no malicious behavior. | ai | |
| source-diff | obfuscated-file:components/Attach/Attach.config.js | AI (source-diff): SWC-compiled CSS template config, not obfuscation; matches package's build pattern. | ai | |
| dependencies | unvetted-dep:@salutejs/plasma-tokens-b2c | AI (dependencies): Same-org monorepo dependency; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@salutejs/plasma-tokens-web | AI (dependencies): Same-org monorepo dependency; stable pattern across all versions of this package. | ai | |
| phantom-deps | phantom-dep:@salutejs/plasma-tokens-web | AI (phantom-deps): Same-org sibling dep; declared but re-exported transitively, stable false positive. | ai | |
| phantom-deps | phantom-dep:@salutejs/plasma-typo | AI (phantom-deps): Same-org sibling dep; declared but re-exported transitively, stable false positive. | ai | |
| provenance | no-provenance | AI (provenance): Large established monorepo; provenance absence is consistent across all versions. | ai |
Versions (showing 51 of 103)
| Version | Deps | Published |
|---|---|---|
| 1.626.0 | 7 / 32 | |
| 1.624.0 | 7 / 32 | |
| 1.623.0 | 7 / 32 | |
| 1.621.0 | 7 / 32 | |
| 1.619.1 | 7 / 32 | |
| 1.619.0 | 7 / 32 | |
| 1.617.0 | 7 / 33 | |
| 1.616.0 | 7 / 33 | |
| 1.615.0 | 7 / 33 | |
| 1.614.0 | 7 / 33 | |
| 1.613.0 | 7 / 33 | |
| 1.612.0 | 7 / 33 | |
| 1.611.0 | 7 / 33 | |
| 1.610.0 | 7 / 33 | |
| 1.609.0 | 7 / 33 | |
| 1.608.0 | 7 / 33 | |
| 1.603.0 | 7 / 33 | |
| 1.602.0 | 7 / 33 | |
| 1.601.0 | 7 / 33 | |
| 1.600.0 | 7 / 33 | |
| 1.599.0 | 7 / 33 | |
| 1.598.0 | 7 / 42 | |
| 1.596.0 | 7 / 42 | |
| 1.350.0 | 6 / 43 | |
| 1.338.0 | 6 / 43 | |
| 1.328.0 | 6 / 43 | |
| 1.327.0 | 6 / 43 | |
| 1.320.0 | 6 / 43 | |
| 1.240.0 | 6 / 36 | |
| 1.237.0 | 6 / 36 | |
| 1.236.2 | 4 / 39 | |
| 1.236.1 | 4 / 39 | |
| 1.236.0 | 4 / 39 | |
| 1.227.0 | 3 / 39 | |
| 1.225.0 | 3 / 39 | |
| 1.221.0 | 3 / 39 | |
| 1.220.0 | 3 / 39 | |
| 1.219.0 | 3 / 39 | |
| 1.218.0 | 3 / 39 | |
| 1.217.0 | 3 / 39 | |
| 1.216.0 | 3 / 39 | |
| 1.215.0 | 3 / 38 | |
| 1.214.0 | 3 / 38 | |
| 1.213.0 | 3 / 38 | |
| 1.212.0 | 3 / 38 | |
| 1.211.0 | 3 / 38 | |
| 1.210.0 | 3 / 38 | |
| 1.209.0 | 3 / 38 | |
| 1.208.2 | 3 / 38 | |
| 1.208.1 | 3 / 38 | |
| 1.208.0 | 3 / 38 |
v1.626.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.624.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.612.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.611.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.610.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.609.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.608.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.603.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.602.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.601.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.600.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.599.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.598.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.596.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.350.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.338.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.328.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.327.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.320.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.240.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.237.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.236.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.236.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.236.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.227.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.225.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.221.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.220.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.219.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.218.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.217.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.216.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.215.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.214.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.213.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.212.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.211.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.210.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.209.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.208.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.208.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.208.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.