← Home

@sanity/ui

49
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sanity-svc.npmsanity-io

Keywords

componentsdesign-systemprimitivesreactsanityui

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/_chunks/theme.d.cts AI (source-diff): Minified/bundled .d.cts type declarations, not obfuscation. ai
source-diff obfuscated-file:dist/theme.d.cts AI (source-diff): Minified/bundled .d.cts type declarations, not obfuscation. ai
source-diff obfuscated-file:dist/index.d.cts AI (source-diff): Minified/bundled .d.cts type declarations, not obfuscation. ai
source-diff obfuscated-file:dist/index.cjs AI (source-diff): Standard bundler output (tsdown/rolldown), not obfuscation. ai
source-diff obfuscated-file:dist/_chunks/useTheme.d.cts AI (source-diff): Minified/bundled .d.cts type declarations, not obfuscation. ai
source-diff obfuscated-file:dist/_chunks/useTheme.d.ts AI (source-diff): Bundled .d.ts type declarations; long re-export line, benign. ai
source-diff obfuscated-file:dist/_chunks/theme.d.mts AI (source-diff): Bundled .d.ts type declarations with long import lines; not obfuscation. ai
source-diff obfuscated-file:dist/_chunks/useTheme.d.mts AI (source-diff): Bundled .d.ts type declarations; long re-export import line, benign. ai
source-diff obfuscated-file:dist/_chunks/theme.d.ts AI (source-diff): Bundled .d.ts type declarations; not obfuscation. ai
source-diff obfuscated-file:dist/useTheme.d.ts AI (source-diff): Minified TS declaration file; benign type re-exports. ai
source-diff obfuscated-file:dist/theme2.d.mts AI (source-diff): Minified TS declaration file from tsdown build; long import lines are build output, not obfuscation. ai
source-diff obfuscated-file:dist/useTheme.d.mts AI (source-diff): Minified TS declaration file; benign type re-exports. ai
source-diff obfuscated-file:dist/theme2.d.ts AI (source-diff): Minified TS declaration file from build; benign. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD with SLSA attestation on canonical Sanity package; legitimate. ai
provenance missing-githead AI (provenance): Expected when publish moves to CI/CD with SLSA provenance. ai
dependencies unvetted-dep:react-refractor AI (dependencies): Well-known syntax highlighting React wrapper; stable dependency for this package. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Established @sanity scoped package; Levenshtein match to unrelated short names is a false positive. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Established @sanity scoped package; Levenshtein match to unrelated short names is a false positive. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Established @sanity scoped package; Levenshtein match to unrelated short names is a false positive. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): Established @sanity scoped package; Levenshtein match to unrelated short names is a false positive. ai
dependencies unvetted-dep:@sanity/color AI (dependencies): First-party @sanity scoped dependency; expected in this ecosystem. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Established @sanity scoped package; Levenshtein match to unrelated short names is a false positive. ai
dependencies unvetted-dep:@sanity/icons AI (dependencies): First-party @sanity scoped dependency; expected in this ecosystem. ai

Versions (showing 49 of 49)

Version Deps Published
3.5.0 10 / 21
3.4.5 10 / 21
3.4.4 9 / 22
3.4.3 9 / 23
3.4.2 9 / 23
3.4.1 9 / 23
3.4.0 9 / 23
3.3.6 9 / 23
3.3.5 9 / 24
3.3.4 9 / 24
3.3.3 9 / 24
3.3.2 9 / 24
3.3.1 9 / 63
3.3.0 9 / 77
3.2.0 9 / 77
3.1.14 9 / 77
3.1.13 9 / 77
3.1.12 9 / 77
3.1.11 9 / 77
3.1.10 9 / 77
3.1.9 9 / 78
3.1.8 9 / 78
3.1.7 9 / 78
3.1.6 9 / 78
3.1.5 9 / 78
3.1.4 9 / 78
3.1.3 9 / 78
3.1.2 9 / 78
3.1.1 9 / 78
3.1.0 9 / 78
3.0.14 9 / 78
3.0.13 9 / 78
3.0.12 9 / 78
3.0.11 9 / 78
3.0.10 9 / 78
3.0.9 9 / 78
3.0.8 9 / 78
3.0.7 9 / 78
3.0.6 9 / 78
3.0.5 9 / 77
3.0.4 9 / 77
3.0.3 9 / 77
3.0.2 9 / 77
3.0.1 9 / 77
3.0.0 9 / 78
2.16.26 9 / 23
2.16.25 9 / 23
2.16.24 9 / 23
2.16.23 9 / 23

v3.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.5

6 findings
HIGH New obfuscated file: dist/_chunks/theme.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/_chunks/useTheme.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/theme.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.4

6 findings
HIGH New obfuscated file: dist/_chunks/theme.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/_chunks/useTheme.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/theme.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.5

6 findings
HIGH New obfuscated file: dist/_chunks/theme.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/_chunks/useTheme.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/_chunks/theme.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/_chunks/useTheme.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v3.3.4

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v3.3.3

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v3.3.2

7 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH Publisher changed: sanity-svc.npm → GitHub Actions (on 2026-07-05) provenance

This version was published by a different npm account than previous versions on 2026-07-05. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/theme2.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/useTheme.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/theme2.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/useTheme.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.1

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH Publisher changed: sanity-svc.npm → GitHub Actions (on 2026-07-03) provenance

This version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.23

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.