← Home

@servicetitan/anvil2

<h1 align="center"> Anvil2 React Library </h1>

61
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

st-teamrgdelatojesspkarpoffseanmadidextersealy

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/RichTextEditor-FSWAVmTe.js AI (source-diff): Bundled Vite/Rollup build output for RichTextEditor, not obfuscation. ai
source-diff obfuscated-file:dist/RichTextEditor-D1IBYQyU.js AI (source-diff): Bundled Vite/Rollup output, not true obfuscation; clean readable imports. ai
npm-metadata no-description AI (npm-metadata): Internal design-system package; benign metadata gap. ai
source-diff obfuscated-file:dist/RichTextEditor-BnFo_55G.js AI (source-diff): Bundled/minified vite build output, not true obfuscation. ai
source-diff obfuscated-file:dist/RichTextEditor-Cm29o9RK.js AI (source-diff): Bundled Vite build output, not true obfuscation; sample shows plain ESM imports. ai
bogus-package bogus-package AI (bogus-package): Established internal design-system package; missing metadata is stylistic, not spam. ai
source-diff obfuscated-file:dist/RichTextEditor-DLIh_mzJ.js AI (source-diff): Vite/Rollup bundled output, not obfuscation; sample shows clean ES module imports. ai
phantom-deps phantom-dep:@tiptap/markdown AI (phantom-deps): New tiptap extension used via config/plugin pattern, matches added feature. ai
source-diff obfuscated-file:dist/RichTextEditor-byoMZaJy.js AI (source-diff): Bundled vite/rollup output for new RichTextEditor feature, not obfuscation. ai
source-diff obfuscated-file:dist/RichTextEditor-DstVbYch.js AI (source-diff): Standard Vite-minified bundle; long lines are from bundled deps, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/RichTextEditor-DUz-bi8H.js AI (source-diff): Standard Vite-minified bundle for RichTextEditor; readable imports confirm legitimate UI component code. ai
phantom-deps phantom-dep:@tiptap/extension-text-style AI (phantom-deps): Tiptap extension suite; stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-placeholder AI (phantom-deps): Tiptap extension suite; stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-drag-handle-react AI (phantom-deps): Tiptap extension suite; stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-task-list AI (phantom-deps): Tiptap extension suite; stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-task-item AI (phantom-deps): Tiptap extension suite; stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-image AI (phantom-deps): Tiptap extension suite; stable false positive. ai
phantom-deps phantom-dep:@tiptap/starter-kit AI (phantom-deps): Same as above — tiptap suite bundled together. ai
phantom-deps phantom-dep:@tiptap/pm AI (phantom-deps): Bundled tiptap deps may be consumed transitively; phantom-dep false positive for this package. ai
phantom-deps phantom-dep:@tiptap/extension-text-align AI (phantom-deps): Tiptap extension suite; stable false positive. ai
phantom-deps phantom-dep:flubber AI (phantom-deps): Bundled UI component library; flubber is a legitimate shape-morphing dep that may be consumed via bundled output rather than direct import. Consistent with other accepted phantom deps in this package. ai
publish-pattern dormant-publish AI (publish-pattern): The gap is between v1.48.0 and v2.6.1 (major version bump). 433 versions in registry confirms active development; dormancy signal is a false positive for a major version transition. ai
phantom-deps phantom-dep:focus-trap-react AI (phantom-deps): focus-trap-react is a legitimate runtime dep for a UI component library (modal/dialog focus management); phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:@react-hook/resize-observer AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
phantom-deps phantom-dep:big.js AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
phantom-deps phantom-dep:motion AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
phantom-deps phantom-dep:classnames AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
phantom-deps phantom-dep:tinycolor2 AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
phantom-deps phantom-dep:react-window AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
phantom-deps phantom-dep:@types/big.js AI (phantom-deps): Framework-scoped package loaded by convention; stable for this package. ai
phantom-deps phantom-dep:@maskito/react AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
phantom-deps phantom-dep:@dnd-kit/sortable AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
phantom-deps phantom-dep:@dnd-kit/utilities AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
phantom-deps phantom-dep:@react-hook/merged-ref AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
phantom-deps phantom-dep:@tanstack/react-virtual AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
phantom-deps phantom-dep:@servicetitan/anvil-fonts AI (phantom-deps): Same org scope as this package; loaded by convention. ai
phantom-deps phantom-dep:@servicetitan/hammer-icon AI (phantom-deps): Same org scope as this package; loaded by convention. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. ai
dependencies unvetted-dep:@types/big.js AI (dependencies): @types/big.js is a DefinitelyTyped type definition package; no security risk. ai
dependencies unvetted-dep:@servicetitan/hammer-token AI (dependencies): Same-org package from ServiceTitan; consistent with the design system's token dependency. ai
dependencies unvetted-dep:@servicetitan/hammer-icon AI (dependencies): Same-org package from ServiceTitan; consistent with the design system's icon dependency. ai
dependencies unvetted-dep:@servicetitan/anvil-fonts AI (dependencies): Same-org package from ServiceTitan; consistent with the design system's font assets dependency. ai
dependencies unvetted-dep:@react-hook/resize-observer AI (dependencies): @react-hook/resize-observer is an established React utility hook; no security risk. ai
dependencies unvetted-dep:@react-hook/merged-ref AI (dependencies): @react-hook/merged-ref is an established React utility hook; no security risk. ai
dependencies unvetted-dep:@maskito/react AI (dependencies): @maskito/react is a legitimate React binding for the maskito library; no security risk. ai
dependencies unvetted-dep:@maskito/core AI (dependencies): @maskito/core is a legitimate, well-maintained input masking library; no security risk. ai
dependencies unvetted-dep:@maskito/kit AI (dependencies): @maskito/kit is a legitimate, well-maintained input masking library; no security risk for this UI component library. ai
provenance no-provenance AI (provenance): Established 742-day-old package with 433 versions; lack of provenance is common and not a risk signal for this package. ai

Versions (showing 61 of 61)

Version Deps Published
3.8.0 44 / 40
3.7.0 44 / 40
3.6.0 44 / 40
3.5.0 43 / 40
3.4.2 43 / 40
3.4.1 43 / 40
3.4.0 43 / 40
3.3.0 43 / 40
3.2.0 43 / 40
3.1.0 43 / 40
3.0.9 43 / 40
3.0.7 43 / 42
3.0.6 43 / 42
3.0.5 43 / 42
3.0.4 43 / 42
3.0.3 43 / 42
3.0.2 43 / 42
3.0.1 29 / 41
3.0.0 29 / 41
2.9.6 29 / 41
2.9.5 29 / 41
2.9.4 29 / 41
2.9.3 29 / 41
2.9.2 29 / 41
2.9.1 29 / 41
2.9.0 29 / 41
2.8.0 30 / 42
2.7.1 29 / 41
2.7.0 29 / 41
2.6.1 29 / 40
2.6.0 29 / 40
2.5.1 29 / 40
2.5.0 29 / 40
2.4.0 29 / 40
2.3.0 29 / 40
2.2.0 29 / 39
2.1.0 29 / 39
2.0.4 29 / 39
2.0.3 29 / 39
2.0.2 29 / 39
2.0.1 29 / 39
2.0.0 29 / 39
1.52.0 29 / 39
1.51.0 29 / 39
1.50.2 28 / 39
1.50.1 28 / 39
1.50.0 28 / 39
1.49.7 28 / 39
1.49.6 28 / 39
1.49.5 28 / 39
1.49.4 28 / 39
1.49.3 28 / 39
1.49.2 28 / 39
1.49.1 28 / 39
1.49.0 28 / 39
1.48.1 27 / 39
1.48.0 27 / 39
1.47.1 27 / 39
1.47.0 27 / 39
1.46.11 27 / 39
1.46.10 27 / 39

v3.8.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.6.0

2 findings
HIGH New obfuscated file: dist/RichTextEditor-byoMZaJy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.2

2 findings
HIGH New obfuscated file: dist/RichTextEditor-DLIh_mzJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.1

2 findings
HIGH New obfuscated file: dist/RichTextEditor-D1IBYQyU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.