@smg-automotive/components
SMG Automotive components library
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Long-established package with consistent publish history; lack of Sigstore attestation is a process gap, not a security signal here. | ai | |
| dependencies | unvetted-dep:@smg-automotive/i18n-pkg | AI (dependencies): Same-org scoped package from a publisher with a clean track record; stable pattern for this library. | ai | |
| dependencies | unvetted-dep:@smg-automotive/phrase-pkg | AI (dependencies): Same-org scoped package from a publisher with a clean track record; stable pattern for this library. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): Package ships a CLI bin; yargs is used in the CLI entry point, not necessarily imported in analyzed source files. | ai | |
| phantom-deps | phantom-dep:fs-extra | AI (phantom-deps): Used in CLI/build tooling scripts; phantom-dep heuristic fires due to config-file references. | ai | |
| phantom-deps | phantom-dep:framer-motion | AI (phantom-deps): framer-motion is a runtime dep used by components; phantom-dep heuristic fires due to indirect import patterns in a component library. | ai | |
| phantom-deps | phantom-dep:merge-json-file | AI (phantom-deps): Used in build/CLI tooling; phantom-dep heuristic fires due to config-file references. | ai | |
| phantom-deps | phantom-dep:@types/fs-extra | AI (phantom-deps): Type-only package; stable false positive for this component library. | ai | |
| phantom-deps | phantom-dep:globals | AI (phantom-deps): Referenced in ESLint config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Chakra UI component library pattern; @emotion/styled is a runtime dep used transitively via Chakra. | ai | |
| phantom-deps | phantom-dep:@smg-automotive/phrase-pkg | AI (phantom-deps): Same-org package; phantom-dep heuristic fires due to config-file references rather than direct imports. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 25.29.0 | 18 / 66 | |
| 25.28.0 | 18 / 66 | |
| 25.27.0 | 18 / 66 | |
| 25.26.3 | 18 / 66 | |
| 25.26.2 | 18 / 66 | |
| 25.26.1 | 18 / 66 | |
| 25.26.0 | 18 / 66 | |
| 25.25.0 | 18 / 66 | |
| 25.24.0 | 18 / 66 | |
| 25.22.4 | 18 / 64 | |
| 25.21.1 | 18 / 64 | |
| 25.19.1 | 18 / 64 | |
| 25.18.1 | 18 / 64 | |
| 25.18.0 | 18 / 64 | |
| 25.17.1 | 18 / 64 | |
| 25.13.0 | 18 / 64 | |
| 25.12.2 | 18 / 64 | |
| 25.10.4 | 18 / 64 | |
| 25.8.0 | 18 / 66 | |
| 25.4.3 | 18 / 66 | |
| 25.4.0 | 18 / 66 | |
| 25.1.3 | 18 / 66 | |
| 25.1.2 | 18 / 66 | |
| 25.0.5 | 18 / 66 | |
| 25.0.4 | 18 / 66 | |
| 25.0.3 | 18 / 66 | |
| 25.0.0 | 18 / 66 |
v25.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.27.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.26.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.26.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.26.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.26.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.25.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.22.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.21.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.19.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.18.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.17.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.13.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.12.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.10.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.4.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.1.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.1.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.0.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.