@scalar/components
Scalars component library
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/components/ScalarIcon/icons/index.js | AI (source-diff): Long line is a generated Vue async-import icon map, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@scalar/oas-utils | AI (phantom-deps): Same-org scoped dep, legit. | ai | |
| source-diff | obfuscated-file:dist/components/ScalarIcon/logos/Elysiajs.svg.js | AI (source-diff): Vue-compiled SVG logo asset; long-line path data is build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components/ScalarIcon/logos/Docusaurus.svg.js | AI (source-diff): Vue-compiled SVG logo asset; long-line path data is build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components/ScalarIcon/logos/Openapi.svg.js | AI (source-diff): Vue-compiled SVG logo asset; long-line path data is build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components/ScalarIcon/logos/Nestjs.svg.js | AI (source-diff): Vue-compiled SVG logo asset; long-line path data is build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components/ScalarIcon/logos/Rust.svg.js | AI (source-diff): Vue-compiled SVG logo asset; long-line path data is build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/programming-language-go-BjshiBx9.cjs | AI (source-diff): Minified Vue SVG icon component; build output, per-file hash names won't recur. | ai | |
| phantom-deps | phantom-dep:@storybook/test | AI (phantom-deps): Referenced in storybook config, not directly imported; stable FP. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @headlessui/tailwindcss is a legitimate Tailwind plugin from the headlessui org, consistent with new build:styles script. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): amritk appears to be a rename of amritkahlon; simultaneous add+remove pattern indicates username change, not takeover. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same as above — paired add/remove strongly suggests username rename, not account compromise. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 35 new files consistent with component library expansion across 2 minor versions; no obfuscation signals present. | ai | |
| phantom-deps | phantom-dep:pretty-bytes | AI (phantom-deps): Build-time dependency; phantom-dep heuristic is not authoritative for this package. | ai | |
| phantom-deps | phantom-dep:@scalar/use-toasts | AI (phantom-deps): Monorepo internal dependency; same org scope, expected pattern for @scalar/* packages. | ai | |
| phantom-deps | phantom-dep:@vueless/storybook-dark-mode | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:cva | AI (dependencies): cva is a well-known class-variance-authority utility; stable dependency for this UI component library. | ai | |
| dependencies | unvetted-dep:@scalar/use-hooks | AI (dependencies): Same org scope (@scalar); sibling package in the monorepo. | ai | |
| dependencies | unvetted-dep:@scalar/themes | AI (dependencies): Same org scope (@scalar); sibling package in the monorepo. | ai | |
| dependencies | unvetted-dep:@scalar/icons | AI (dependencies): Same org scope (@scalar); sibling package in the monorepo. | ai | |
| phantom-deps | phantom-dep:vue-component-type-helpers | AI (phantom-deps): Referenced in config/type files; not a runtime import — stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@scalar/themes | AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic is a stable false positive for this monorepo package. | ai |
Versions (showing 36 of 236)
| Version | Deps | Published |
|---|---|---|
| 0.12.10 | 11 / 31 | |
| 0.12.9 | 11 / 32 | |
| 0.12.8 | 11 / 32 | |
| 0.12.7 | 11 / 32 | |
| 0.12.6 | 11 / 32 | |
| 0.12.5 | 11 / 32 | |
| 0.12.4 | 12 / 32 | |
| 0.12.3 | 12 / 33 | |
| 0.12.1 | 12 / 33 | |
| 0.12.0 | 12 / 33 | |
| 0.11.6 | 11 / 33 | |
| 0.11.5 | 11 / 33 | |
| 0.11.4 | 11 / 33 | |
| 0.11.3 | 11 / 33 | |
| 0.11.2 | 11 / 33 | |
| 0.11.1 | 10 / 34 | |
| 0.11.0 | 10 / 34 | |
| 0.10.1 | 10 / 32 | |
| 0.10.0 | 10 / 32 | |
| 0.9.0 | 10 / 31 | |
| 0.8.0 | 10 / 32 | |
| 0.7.15 | 10 / 32 | |
| 0.7.14 | 10 / 32 | |
| 0.7.13 | 10 / 32 | |
| 0.7.12 | 10 / 32 | |
| 0.7.11 | 10 / 32 | |
| 0.7.10 | 10 / 32 | |
| 0.7.9 | 10 / 32 | |
| 0.7.8 | 10 / 32 | |
| 0.7.7 | 10 / 32 | |
| 0.7.6 | 10 / 32 | |
| 0.7.5 | 10 / 32 | |
| 0.7.4 | 10 / 32 | |
| 0.7.3 | 10 / 32 | |
| 0.6.1 | 9 / 32 | |
| 0.6.0 | 9 / 32 |
v0.12.10
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.9
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.8
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.7
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.4
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.4
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.