← Home

@smg-automotive/components

SMG Automotive components library

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

smg-automotive-engineering

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): CI pipeline change for trusted internal publisher, not a provenance regression. ai
phantom-deps phantom-dep:@chakra-ui/cli AI (phantom-deps): Used by typegen script via pnpm exec chakra, not a source import. ai
phantom-deps phantom-dep:motion AI (phantom-deps): New UI animation lib replacing framer-motion; used in bundled build output. ai
source-diff obfuscated-file:dist/index.d.mts AI (source-diff): Long-line .d.mts type declarations from rollup-plugin-dts, not obfuscated code. ai
install-scripts install-script:postinstall FP: postinstall = `npm run typegen` (package own codegen). No net/exec. sean
provenance no-provenance AI (provenance): Long-established package with consistent publish history; lack of Sigstore attestation is a process gap, not a security signal here. ai
dependencies unvetted-dep:@smg-automotive/i18n-pkg AI (dependencies): Same-org scoped package from a publisher with a clean track record; stable pattern for this library. ai
dependencies unvetted-dep:@smg-automotive/phrase-pkg AI (dependencies): Same-org scoped package from a publisher with a clean track record; stable pattern for this library. ai
phantom-deps phantom-dep:framer-motion AI (phantom-deps): framer-motion is a runtime dep used by components; phantom-dep heuristic fires due to indirect import patterns in a component library. ai
phantom-deps phantom-dep:@emotion/styled AI (phantom-deps): Chakra UI component library pattern; @emotion/styled is a runtime dep used transitively via Chakra. ai
phantom-deps phantom-dep:merge-json-file AI (phantom-deps): Used in build/CLI tooling; phantom-dep heuristic fires due to config-file references. ai
phantom-deps phantom-dep:globals AI (phantom-deps): Referenced in ESLint config files; stable false positive for this package. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): Used in CLI/build tooling scripts; phantom-dep heuristic fires due to config-file references. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): Package ships a CLI bin; yargs is used in the CLI entry point, not necessarily imported in analyzed source files. ai
phantom-deps phantom-dep:@smg-automotive/phrase-pkg AI (phantom-deps): Same-org package; phantom-dep heuristic fires due to config-file references rather than direct imports. ai
phantom-deps phantom-dep:@types/fs-extra AI (phantom-deps): Type-only package; stable false positive for this component library. ai

Versions (showing 51 of 97)

View all versions
Version Deps Published
27.3.3 15 / 70
27.3.2 15 / 70
27.3.1 15 / 70
27.3.0 15 / 70
27.2.0 15 / 70
27.1.2 15 / 70
27.1.1 15 / 70
27.1.0 15 / 66
27.0.0 15 / 66
26.1.1 15 / 66
26.1.0 15 / 66
26.0.3 15 / 66
26.0.2 15 / 66
26.0.1 15 / 66
26.0.0 15 / 66
25.32.0 15 / 66
25.31.0 15 / 66
25.30.0 18 / 66
25.29.0 18 / 66
25.28.0 18 / 66
25.27.0 18 / 66
25.26.3 18 / 66
25.26.2 18 / 66
25.26.1 18 / 66
25.26.0 18 / 66
25.25.0 18 / 66
25.24.0 18 / 66
25.23.0 18 / 64
25.22.6 18 / 64
25.22.5 18 / 64
25.22.4 18 / 64
25.22.3 18 / 64
25.22.2 18 / 64
25.22.1 18 / 64
25.22.0 18 / 64
25.21.1 18 / 64
25.21.0 18 / 64
25.20.0 18 / 64
25.19.4 18 / 64
25.19.3 18 / 64
25.19.2 18 / 64
25.19.1 18 / 64
25.19.0 18 / 64
25.18.1 18 / 64
25.18.0 18 / 64
25.17.1 18 / 64
25.17.0 18 / 64
25.16.1 18 / 64
25.16.0 18 / 64
25.15.3 18 / 64
25.15.2 18 / 64

v27.3.3

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.3.2

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.3.1

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.3.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.2.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.1.2

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.1.1

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v27.0.0

2 findings
HIGH Package has 'postinstall' script install-scripts

[Reject — re-review on republish] (prior reject: AI (install-scripts): Postinstall runs npx chakra typegen on consumer machines — new addition, not appropriate for a UI component library.) Script: npm run typegen

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.1.1

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: npm run typegen

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.1.0

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: npm run typegen

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.0.3

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: npm run typegen

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.0.2

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: npm run typegen

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.0.1

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: npm run typegen

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.0.0

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: npm run typegen

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.32.0

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: npm run typegen

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.26.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.26.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.26.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.25.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.24.0

2 findings
HIGH New obfuscated file: dist/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.23.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.22.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.22.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.22.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.22.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.22.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.22.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.22.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.21.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.21.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.20.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.19.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.19.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.19.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.19.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.19.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.18.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.18.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.17.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.17.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.16.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.16.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.15.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.15.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.