@servicetitan/anvil2
<h1 align="center"> Anvil2 React Library </h1>
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/RichTextEditor-FSWAVmTe.js | AI (source-diff): Bundled Vite/Rollup build output for RichTextEditor, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/RichTextEditor-D1IBYQyU.js | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation; clean readable imports. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Internal design-system package; benign metadata gap. | ai | |
| source-diff | obfuscated-file:dist/RichTextEditor-BnFo_55G.js | AI (source-diff): Bundled/minified vite build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/RichTextEditor-Cm29o9RK.js | AI (source-diff): Bundled Vite build output, not true obfuscation; sample shows plain ESM imports. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established internal design-system package; missing metadata is stylistic, not spam. | ai | |
| source-diff | obfuscated-file:dist/RichTextEditor-DLIh_mzJ.js | AI (source-diff): Vite/Rollup bundled output, not obfuscation; sample shows clean ES module imports. | ai | |
| phantom-deps | phantom-dep:@tiptap/markdown | AI (phantom-deps): New tiptap extension used via config/plugin pattern, matches added feature. | ai | |
| source-diff | obfuscated-file:dist/RichTextEditor-byoMZaJy.js | AI (source-diff): Bundled vite/rollup output for new RichTextEditor feature, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/RichTextEditor-DstVbYch.js | AI (source-diff): Standard Vite-minified bundle; long lines are from bundled deps, not obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/RichTextEditor-DUz-bi8H.js | AI (source-diff): Standard Vite-minified bundle for RichTextEditor; readable imports confirm legitimate UI component code. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-text-style | AI (phantom-deps): Tiptap extension suite; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-placeholder | AI (phantom-deps): Tiptap extension suite; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-drag-handle-react | AI (phantom-deps): Tiptap extension suite; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-task-list | AI (phantom-deps): Tiptap extension suite; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-task-item | AI (phantom-deps): Tiptap extension suite; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-image | AI (phantom-deps): Tiptap extension suite; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tiptap/starter-kit | AI (phantom-deps): Same as above — tiptap suite bundled together. | ai | |
| phantom-deps | phantom-dep:@tiptap/pm | AI (phantom-deps): Bundled tiptap deps may be consumed transitively; phantom-dep false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-text-align | AI (phantom-deps): Tiptap extension suite; stable false positive. | ai | |
| phantom-deps | phantom-dep:flubber | AI (phantom-deps): Bundled UI component library; flubber is a legitimate shape-morphing dep that may be consumed via bundled output rather than direct import. Consistent with other accepted phantom deps in this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): The gap is between v1.48.0 and v2.6.1 (major version bump). 433 versions in registry confirms active development; dormancy signal is a false positive for a major version transition. | ai | |
| phantom-deps | phantom-dep:focus-trap-react | AI (phantom-deps): focus-trap-react is a legitimate runtime dep for a UI component library (modal/dialog focus management); phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:@react-hook/resize-observer | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| phantom-deps | phantom-dep:big.js | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| phantom-deps | phantom-dep:motion | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| phantom-deps | phantom-dep:classnames | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| phantom-deps | phantom-dep:tinycolor2 | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| phantom-deps | phantom-dep:react-window | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| phantom-deps | phantom-dep:@types/big.js | AI (phantom-deps): Framework-scoped package loaded by convention; stable for this package. | ai | |
| phantom-deps | phantom-dep:@maskito/react | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/sortable | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/utilities | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| phantom-deps | phantom-dep:@react-hook/merged-ref | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-virtual | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| phantom-deps | phantom-dep:@servicetitan/anvil-fonts | AI (phantom-deps): Same org scope as this package; loaded by convention. | ai | |
| phantom-deps | phantom-dep:@servicetitan/hammer-icon | AI (phantom-deps): Same org scope as this package; loaded by convention. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Phantom dep in config/build context; typical for established UI libraries. | ai | |
| dependencies | unvetted-dep:@types/big.js | AI (dependencies): @types/big.js is a DefinitelyTyped type definition package; no security risk. | ai | |
| dependencies | unvetted-dep:@servicetitan/hammer-token | AI (dependencies): Same-org package from ServiceTitan; consistent with the design system's token dependency. | ai | |
| dependencies | unvetted-dep:@servicetitan/hammer-icon | AI (dependencies): Same-org package from ServiceTitan; consistent with the design system's icon dependency. | ai | |
| dependencies | unvetted-dep:@servicetitan/anvil-fonts | AI (dependencies): Same-org package from ServiceTitan; consistent with the design system's font assets dependency. | ai | |
| dependencies | unvetted-dep:@react-hook/resize-observer | AI (dependencies): @react-hook/resize-observer is an established React utility hook; no security risk. | ai | |
| dependencies | unvetted-dep:@react-hook/merged-ref | AI (dependencies): @react-hook/merged-ref is an established React utility hook; no security risk. | ai | |
| dependencies | unvetted-dep:@maskito/react | AI (dependencies): @maskito/react is a legitimate React binding for the maskito library; no security risk. | ai | |
| dependencies | unvetted-dep:@maskito/core | AI (dependencies): @maskito/core is a legitimate, well-maintained input masking library; no security risk. | ai | |
| dependencies | unvetted-dep:@maskito/kit | AI (dependencies): @maskito/kit is a legitimate, well-maintained input masking library; no security risk for this UI component library. | ai | |
| provenance | no-provenance | AI (provenance): Established 742-day-old package with 433 versions; lack of provenance is common and not a risk signal for this package. | ai |
Versions (showing 61 of 61)
| Version | Deps | Published |
|---|---|---|
| 3.8.0 | 44 / 40 | |
| 3.7.0 | 44 / 40 | |
| 3.6.0 | 44 / 40 | |
| 3.5.0 | 43 / 40 | |
| 3.4.2 | 43 / 40 | |
| 3.4.1 | 43 / 40 | |
| 3.4.0 | 43 / 40 | |
| 3.3.0 | 43 / 40 | |
| 3.2.0 | 43 / 40 | |
| 3.1.0 | 43 / 40 | |
| 3.0.9 | 43 / 40 | |
| 3.0.7 | 43 / 42 | |
| 3.0.6 | 43 / 42 | |
| 3.0.5 | 43 / 42 | |
| 3.0.4 | 43 / 42 | |
| 3.0.3 | 43 / 42 | |
| 3.0.2 | 43 / 42 | |
| 3.0.1 | 29 / 41 | |
| 3.0.0 | 29 / 41 | |
| 2.9.6 | 29 / 41 | |
| 2.9.5 | 29 / 41 | |
| 2.9.4 | 29 / 41 | |
| 2.9.3 | 29 / 41 | |
| 2.9.2 | 29 / 41 | |
| 2.9.1 | 29 / 41 | |
| 2.9.0 | 29 / 41 | |
| 2.8.0 | 30 / 42 | |
| 2.7.1 | 29 / 41 | |
| 2.7.0 | 29 / 41 | |
| 2.6.1 | 29 / 40 | |
| 2.6.0 | 29 / 40 | |
| 2.5.1 | 29 / 40 | |
| 2.5.0 | 29 / 40 | |
| 2.4.0 | 29 / 40 | |
| 2.3.0 | 29 / 40 | |
| 2.2.0 | 29 / 39 | |
| 2.1.0 | 29 / 39 | |
| 2.0.4 | 29 / 39 | |
| 2.0.3 | 29 / 39 | |
| 2.0.2 | 29 / 39 | |
| 2.0.1 | 29 / 39 | |
| 2.0.0 | 29 / 39 | |
| 1.52.0 | 29 / 39 | |
| 1.51.0 | 29 / 39 | |
| 1.50.2 | 28 / 39 | |
| 1.50.1 | 28 / 39 | |
| 1.50.0 | 28 / 39 | |
| 1.49.7 | 28 / 39 | |
| 1.49.6 | 28 / 39 | |
| 1.49.5 | 28 / 39 | |
| 1.49.4 | 28 / 39 | |
| 1.49.3 | 28 / 39 | |
| 1.49.2 | 28 / 39 | |
| 1.49.1 | 28 / 39 | |
| 1.49.0 | 28 / 39 | |
| 1.48.1 | 27 / 39 | |
| 1.48.0 | 27 / 39 | |
| 1.47.1 | 27 / 39 | |
| 1.47.0 | 27 / 39 | |
| 1.46.11 | 27 / 39 | |
| 1.46.10 | 27 / 39 |
v3.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.