@scalar/components
Scalars component library
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/components/ScalarIcon/icons/index.js | AI (source-diff): Long line is a generated Vue async-import icon map, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@scalar/oas-utils | AI (phantom-deps): Same-org scoped dep, legit. | ai | |
| source-diff | obfuscated-file:dist/components/ScalarIcon/logos/Elysiajs.svg.js | AI (source-diff): Vue-compiled SVG logo asset; long-line path data is build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components/ScalarIcon/logos/Docusaurus.svg.js | AI (source-diff): Vue-compiled SVG logo asset; long-line path data is build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components/ScalarIcon/logos/Openapi.svg.js | AI (source-diff): Vue-compiled SVG logo asset; long-line path data is build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components/ScalarIcon/logos/Nestjs.svg.js | AI (source-diff): Vue-compiled SVG logo asset; long-line path data is build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components/ScalarIcon/logos/Rust.svg.js | AI (source-diff): Vue-compiled SVG logo asset; long-line path data is build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/programming-language-go-BjshiBx9.cjs | AI (source-diff): Minified Vue SVG icon component; build output, per-file hash names won't recur. | ai | |
| phantom-deps | phantom-dep:@storybook/test | AI (phantom-deps): Referenced in storybook config, not directly imported; stable FP. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @headlessui/tailwindcss is a legitimate Tailwind plugin from the headlessui org, consistent with new build:styles script. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): amritk appears to be a rename of amritkahlon; simultaneous add+remove pattern indicates username change, not takeover. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same as above — paired add/remove strongly suggests username rename, not account compromise. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 35 new files consistent with component library expansion across 2 minor versions; no obfuscation signals present. | ai | |
| phantom-deps | phantom-dep:pretty-bytes | AI (phantom-deps): Build-time dependency; phantom-dep heuristic is not authoritative for this package. | ai | |
| phantom-deps | phantom-dep:@scalar/use-toasts | AI (phantom-deps): Monorepo internal dependency; same org scope, expected pattern for @scalar/* packages. | ai | |
| phantom-deps | phantom-dep:@vueless/storybook-dark-mode | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:cva | AI (dependencies): cva is a well-known class-variance-authority utility; stable dependency for this UI component library. | ai | |
| dependencies | unvetted-dep:@scalar/use-hooks | AI (dependencies): Same org scope (@scalar); sibling package in the monorepo. | ai | |
| dependencies | unvetted-dep:@scalar/themes | AI (dependencies): Same org scope (@scalar); sibling package in the monorepo. | ai | |
| dependencies | unvetted-dep:@scalar/icons | AI (dependencies): Same org scope (@scalar); sibling package in the monorepo. | ai | |
| phantom-deps | phantom-dep:vue-component-type-helpers | AI (phantom-deps): Referenced in config/type files; not a runtime import — stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@scalar/themes | AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic is a stable false positive for this monorepo package. | ai |
Versions (showing 51 of 236)
| Version | Deps | Published |
|---|---|---|
| 0.27.9 | 14 / 19 | |
| 0.27.8 | 14 / 19 | |
| 0.27.7 | 14 / 19 | |
| 0.26.1 | 15 / 19 | |
| 0.25.0 | 15 / 19 | |
| 0.24.4 | 15 / 19 | |
| 0.24.2 | 15 / 19 | |
| 0.24.1 | 14 / 19 | |
| 0.24.0 | 14 / 19 | |
| 0.23.0 | 14 / 19 | |
| 0.22.5 | 14 / 19 | |
| 0.22.3 | 14 / 19 | |
| 0.22.2 | 14 / 19 | |
| 0.22.1 | 14 / 19 | |
| 0.21.3 | 14 / 19 | |
| 0.21.2 | 15 / 18 | |
| 0.20.12 | 15 / 18 | |
| 0.20.11 | 15 / 18 | |
| 0.20.10 | 15 / 18 | |
| 0.20.9 | 16 / 19 | |
| 0.20.8 | 16 / 19 | |
| 0.20.7 | 16 / 19 | |
| 0.20.6 | 16 / 19 | |
| 0.20.5 | 16 / 19 | |
| 0.20.4 | 16 / 19 | |
| 0.20.3 | 16 / 19 | |
| 0.20.2 | 16 / 19 | |
| 0.20.1 | 16 / 19 | |
| 0.20.0 | 16 / 19 | |
| 0.19.15 | 16 / 19 | |
| 0.19.14 | 16 / 19 | |
| 0.19.13 | 16 / 19 | |
| 0.19.12 | 16 / 19 | |
| 0.19.10 | 16 / 19 | |
| 0.19.9 | 16 / 19 | |
| 0.19.8 | 16 / 19 | |
| 0.19.7 | 16 / 19 | |
| 0.19.4 | 16 / 19 | |
| 0.19.2 | 16 / 19 | |
| 0.19.1 | 16 / 19 | |
| 0.19.0 | 16 / 19 | |
| 0.18.0 | 16 / 19 | |
| 0.17.6 | 16 / 19 | |
| 0.17.5 | 16 / 19 | |
| 0.17.4 | 16 / 19 | |
| 0.17.3 | 16 / 19 | |
| 0.17.2 | 16 / 19 | |
| 0.17.1 | 16 / 19 | |
| 0.17.0 | 16 / 19 | |
| 0.16.32 | 16 / 19 | |
| 0.16.31 | 16 / 19 |
v0.27.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.27.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.27.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.25.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.17.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.17.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.17.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.17.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.17.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.16.32
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.16.31
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.