@salutejs/plasma-web
Salute Design System / React UI kit for web applications
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/styled-components/cjs/components/Attach/Attach.config.js | AI (source-diff): SWC-compiled styled-components config, long CSS template literal lines, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/styled-components/cjs/components/Autocomplete/Autocomplete.config.js | AI (source-diff): Same build-output pattern as sibling config files. | ai | |
| source-diff | obfuscated-file:components/DatePicker/DatePicker.config.js | AI (source-diff): Compiled styled-components template literals, not obfuscation. | ai | |
| source-diff | obfuscated-file:es/components/DatePicker/DatePicker.config.js | AI (source-diff): Compiled styled-components template literals, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/Range/Range.config.js | AI (source-diff): Babel/styled-components tagged-template CSS config, not obfuscation. | ai | |
| source-diff | obfuscated-file:es/components/Slider/Slider.config.js | AI (source-diff): Babel/styled-components tagged-template CSS config, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/Slider/Slider.config.js | AI (source-diff): Babel/styled-components tagged-template CSS config, not obfuscation. | ai | |
| source-diff | obfuscated-file:es/components/Range/Range.config.js | AI (source-diff): Babel/styled-components tagged-template CSS config, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/Attach/Attach.config.js | AI (source-diff): SWC-compiled styled-components config, not obfuscation; consistent codegen pattern across package. | ai | |
| source-diff | obfuscated-file:components/Autocomplete/Autocomplete.config.js | AI (source-diff): Same SWC-compiled config pattern as sibling components. | ai | |
| dependencies | unvetted-dep:@salutejs/plasma-tokens-b2c | AI (dependencies): Same-org (@salutejs) token package; consistent pattern across this monorepo's releases. | ai | |
| dependencies | unvetted-dep:@salutejs/plasma-tokens-web | AI (dependencies): Same-org (@salutejs) token package; consistent pattern across this monorepo's releases. | ai | |
| provenance | no-provenance | AI (provenance): Large established monorepo package; lack of provenance is consistent across all versions and not a risk indicator here. | ai | |
| phantom-deps | phantom-dep:@salutejs/plasma-typo | AI (phantom-deps): Same-org monorepo dep; may be re-exported transitively rather than directly imported. | ai | |
| phantom-deps | phantom-dep:@salutejs/plasma-tokens-b2c | AI (phantom-deps): Same-org monorepo dep; consistent with design-token re-export pattern. | ai | |
| phantom-deps | phantom-dep:@salutejs/plasma-tokens-b2b | AI (phantom-deps): Same-org monorepo dep; consistent with design-token re-export pattern. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 1.628.0 | 8 / 30 | |
| 1.626.0 | 8 / 30 | |
| 1.625.0 | 8 / 30 | |
| 1.623.0 | 8 / 30 | |
| 1.621.1 | 8 / 30 | |
| 1.621.0 | 8 / 30 | |
| 1.619.0 | 8 / 31 | |
| 1.618.0 | 8 / 31 | |
| 1.617.0 | 8 / 31 | |
| 1.616.0 | 8 / 31 | |
| 1.615.0 | 8 / 31 | |
| 1.614.0 | 8 / 31 | |
| 1.613.0 | 8 / 31 | |
| 1.612.0 | 8 / 31 | |
| 1.611.0 | 8 / 31 | |
| 1.610.0 | 8 / 31 | |
| 1.605.0 | 8 / 31 | |
| 1.604.0 | 8 / 31 | |
| 1.603.0 | 8 / 31 | |
| 1.602.0 | 8 / 31 | |
| 1.601.0 | 8 / 31 | |
| 1.600.0 | 8 / 40 | |
| 1.598.0 | 8 / 40 | |
| 1.351.0 | 7 / 40 | |
| 1.339.0 | 7 / 40 | |
| 1.329.0 | 7 / 40 | |
| 1.328.0 | 7 / 40 | |
| 1.321.0 | 7 / 40 |
v1.628.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.626.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.614.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.613.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.612.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.611.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.610.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.605.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.604.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.603.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.602.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.601.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.600.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.598.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.351.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.339.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.329.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.328.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.321.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.