@sisense/sdk-ui-preact
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/use-hover-CkmV6eu9-5f0519a8.cjs | AI (source-diff): Same as ESM counterpart; CJS bundle of UI library with normal async patterns. No dropper behavior. | ai | |
| source-diff | net-exec-file:dist/use-hover-CkmV6eu9-214a1e6d.js | AI (source-diff): Network calls and dynamic code in bundled UI library are legitimate (fetch for data, Promise/async patterns). No dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/use-hover-CkmV6eu9-214a1e6d.js | AI (source-diff): Standard Vite minified bundle chunk; not obfuscated malware. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/use-hover-CkmV6eu9-5f0519a8.cjs | AI (source-diff): Standard Vite minified CJS bundle chunk; not obfuscated malware. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/index-D7mHzfx0-52769d88.cjs | AI (source-diff): Minified index bundle; content shows SDK error strings and UI logic, not malware. | ai | |
| source-diff | net-exec-file:dist/use-hover-mptQLQ4S-fa13b5dc.cjs | AI (source-diff): Network calls and dynamic execution are part of Preact/React UI rendering; no dropper pattern in samples. | ai | |
| source-diff | net-exec-file:dist/use-hover-mptQLQ4S-feb781c7.js | AI (source-diff): Network calls and dynamic execution are part of Preact/React UI rendering; no dropper pattern in samples. | ai | |
| source-diff | obfuscated-file:dist/preact.module-8d1bbc3f.cjs | AI (source-diff): Minified Preact core module; standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/use-hover-mptQLQ4S-fa13b5dc.cjs | AI (source-diff): Minified Vite bundle chunk; content is Preact/i18n library code, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/use-hover-mptQLQ4S-feb781c7.js | AI (source-diff): Minified Vite bundle chunk; content is Preact/i18n library code, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/compat.module-b324511a.cjs | AI (source-diff): Minified Preact compat module; standard build artifact for this SDK package. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a peer/compat dependency for Preact's React compatibility layer; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:preact-render-to-string | AI (phantom-deps): preact-render-to-string is used in build/config context for SSR support; stable false positive for this package. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 2.27.0 | 5 / 11 | |
| 2.26.0 | 5 / 11 | |
| 2.25.0 | 5 / 11 | |
| 2.24.0 | 5 / 11 |
v2.27.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.26.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.25.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.