← Home

@simplybusiness/theme-simplybusiness

3
Versions
UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

simplybusiness-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@simplybusiness/mobius-chatbot AI (dependencies): Same-org scoped dependency; consistent with this theme package's design across all versions. ai
dependencies unvetted-dep:@simplybusiness/mobius-journey AI (dependencies): Same-org scoped dependency; consistent with this theme package's design across all versions. ai
dependencies unvetted-dep:@simplybusiness/mobius-interventions AI (dependencies): Same-org scoped dependency; consistent with this theme package's design across all versions. ai
phantom-deps phantom-dep:@simplybusiness/mobius-journey AI (phantom-deps): Same-org CSS theme; deps are peer/transitive design-system packages, not directly imported in JS. ai
phantom-deps phantom-dep:@simplybusiness/mobius-datepicker AI (phantom-deps): Same-org CSS theme; deps are peer/transitive design-system packages, not directly imported in JS. ai
phantom-deps phantom-dep:@simplybusiness/mobius AI (phantom-deps): Same-org CSS theme; deps are peer/transitive design-system packages, not directly imported in JS. ai
bogus-package bogus-package AI (bogus-package): Internal scoped CSS theme package; no public repo/description is expected for org-internal tooling. ai
phantom-deps phantom-dep:@simplybusiness/mobius-interventions AI (phantom-deps): Same-org CSS theme; deps are peer/transitive design-system packages, not directly imported in JS. ai
phantom-deps phantom-dep:@simplybusiness/theme-core AI (phantom-deps): Same-org CSS theme; deps are peer/transitive design-system packages, not directly imported in JS. ai
phantom-deps phantom-dep:@simplybusiness/mobius-chatbot AI (phantom-deps): Same-org CSS theme; deps are peer/transitive design-system packages, not directly imported in JS. ai

Versions (showing 3 of 3)

Version Deps Published
3.0.72 6 / 1
3.0.70 6 / 1
3.0.33 6 / 3

v3.0.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.