@smg-automotive/components
SMG Automotive components library
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): CI pipeline change for trusted internal publisher, not a provenance regression. | ai | |
| phantom-deps | phantom-dep:@chakra-ui/cli | AI (phantom-deps): Used by typegen script via pnpm exec chakra, not a source import. | ai | |
| phantom-deps | phantom-dep:motion | AI (phantom-deps): New UI animation lib replacing framer-motion; used in bundled build output. | ai | |
| source-diff | obfuscated-file:dist/index.d.mts | AI (source-diff): Long-line .d.mts type declarations from rollup-plugin-dts, not obfuscated code. | ai | |
| install-scripts | install-script:postinstall | FP: postinstall = `npm run typegen` (package own codegen). No net/exec. | sean | |
| provenance | no-provenance | AI (provenance): Long-established package with consistent publish history; lack of Sigstore attestation is a process gap, not a security signal here. | ai | |
| dependencies | unvetted-dep:@smg-automotive/i18n-pkg | AI (dependencies): Same-org scoped package from a publisher with a clean track record; stable pattern for this library. | ai | |
| dependencies | unvetted-dep:@smg-automotive/phrase-pkg | AI (dependencies): Same-org scoped package from a publisher with a clean track record; stable pattern for this library. | ai | |
| phantom-deps | phantom-dep:framer-motion | AI (phantom-deps): framer-motion is a runtime dep used by components; phantom-dep heuristic fires due to indirect import patterns in a component library. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Chakra UI component library pattern; @emotion/styled is a runtime dep used transitively via Chakra. | ai | |
| phantom-deps | phantom-dep:merge-json-file | AI (phantom-deps): Used in build/CLI tooling; phantom-dep heuristic fires due to config-file references. | ai | |
| phantom-deps | phantom-dep:globals | AI (phantom-deps): Referenced in ESLint config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:fs-extra | AI (phantom-deps): Used in CLI/build tooling scripts; phantom-dep heuristic fires due to config-file references. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): Package ships a CLI bin; yargs is used in the CLI entry point, not necessarily imported in analyzed source files. | ai | |
| phantom-deps | phantom-dep:@smg-automotive/phrase-pkg | AI (phantom-deps): Same-org package; phantom-dep heuristic fires due to config-file references rather than direct imports. | ai | |
| phantom-deps | phantom-dep:@types/fs-extra | AI (phantom-deps): Type-only package; stable false positive for this component library. | ai |
Versions (showing 51 of 97)
| Version | Deps | Published |
|---|---|---|
| 27.3.3 | 15 / 70 | |
| 27.3.2 | 15 / 70 | |
| 27.3.1 | 15 / 70 | |
| 27.3.0 | 15 / 70 | |
| 27.2.0 | 15 / 70 | |
| 27.1.2 | 15 / 70 | |
| 27.1.1 | 15 / 70 | |
| 27.1.0 | 15 / 66 | |
| 27.0.0 | 15 / 66 | |
| 26.1.1 | 15 / 66 | |
| 26.1.0 | 15 / 66 | |
| 26.0.3 | 15 / 66 | |
| 26.0.2 | 15 / 66 | |
| 26.0.1 | 15 / 66 | |
| 26.0.0 | 15 / 66 | |
| 25.32.0 | 15 / 66 | |
| 25.31.0 | 15 / 66 | |
| 25.30.0 | 18 / 66 | |
| 25.29.0 | 18 / 66 | |
| 25.28.0 | 18 / 66 | |
| 25.27.0 | 18 / 66 | |
| 25.26.3 | 18 / 66 | |
| 25.26.2 | 18 / 66 | |
| 25.26.1 | 18 / 66 | |
| 25.26.0 | 18 / 66 | |
| 25.25.0 | 18 / 66 | |
| 25.24.0 | 18 / 66 | |
| 25.23.0 | 18 / 64 | |
| 25.22.6 | 18 / 64 | |
| 25.22.5 | 18 / 64 | |
| 25.22.4 | 18 / 64 | |
| 25.22.3 | 18 / 64 | |
| 25.22.2 | 18 / 64 | |
| 25.22.1 | 18 / 64 | |
| 25.22.0 | 18 / 64 | |
| 25.21.1 | 18 / 64 | |
| 25.21.0 | 18 / 64 | |
| 25.20.0 | 18 / 64 | |
| 25.19.4 | 18 / 64 | |
| 25.19.3 | 18 / 64 | |
| 25.19.2 | 18 / 64 | |
| 25.19.1 | 18 / 64 | |
| 25.19.0 | 18 / 64 | |
| 25.18.1 | 18 / 64 | |
| 25.18.0 | 18 / 64 | |
| 25.17.1 | 18 / 64 | |
| 25.17.0 | 18 / 64 | |
| 25.16.1 | 18 / 64 | |
| 25.16.0 | 18 / 64 | |
| 25.15.3 | 18 / 64 | |
| 25.15.2 | 18 / 64 |
v27.3.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.3.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.3.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.3.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.2.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.1.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.1.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.0.0
2 findings[Reject — re-review on republish] (prior reject: AI (install-scripts): Postinstall runs npx chakra typegen on consumer machines — new addition, not appropriate for a UI component library.) Script: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.1.1
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.1.0
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.0.3
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.0.2
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.0.1
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.0.0
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.32.0
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.26.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.26.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.24.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.23.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.21.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.20.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.19.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.19.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.19.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.19.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.19.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.18.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.17.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.15.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.15.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.