@smg-automotive/components
SMG Automotive components library
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): CI pipeline change for trusted internal publisher, not a provenance regression. | ai | |
| phantom-deps | phantom-dep:@chakra-ui/cli | AI (phantom-deps): Used by typegen script via pnpm exec chakra, not a source import. | ai | |
| phantom-deps | phantom-dep:motion | AI (phantom-deps): New UI animation lib replacing framer-motion; used in bundled build output. | ai | |
| source-diff | obfuscated-file:dist/index.d.mts | AI (source-diff): Long-line .d.mts type declarations from rollup-plugin-dts, not obfuscated code. | ai | |
| install-scripts | install-script:postinstall | FP: postinstall = `npm run typegen` (package own codegen). No net/exec. | sean | |
| provenance | no-provenance | AI (provenance): Long-established package with consistent publish history; lack of Sigstore attestation is a process gap, not a security signal here. | ai | |
| dependencies | unvetted-dep:@smg-automotive/i18n-pkg | AI (dependencies): Same-org scoped package from a publisher with a clean track record; stable pattern for this library. | ai | |
| dependencies | unvetted-dep:@smg-automotive/phrase-pkg | AI (dependencies): Same-org scoped package from a publisher with a clean track record; stable pattern for this library. | ai | |
| phantom-deps | phantom-dep:framer-motion | AI (phantom-deps): framer-motion is a runtime dep used by components; phantom-dep heuristic fires due to indirect import patterns in a component library. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Chakra UI component library pattern; @emotion/styled is a runtime dep used transitively via Chakra. | ai | |
| phantom-deps | phantom-dep:merge-json-file | AI (phantom-deps): Used in build/CLI tooling; phantom-dep heuristic fires due to config-file references. | ai | |
| phantom-deps | phantom-dep:globals | AI (phantom-deps): Referenced in ESLint config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:fs-extra | AI (phantom-deps): Used in CLI/build tooling scripts; phantom-dep heuristic fires due to config-file references. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): Package ships a CLI bin; yargs is used in the CLI entry point, not necessarily imported in analyzed source files. | ai | |
| phantom-deps | phantom-dep:@smg-automotive/phrase-pkg | AI (phantom-deps): Same-org package; phantom-dep heuristic fires due to config-file references rather than direct imports. | ai | |
| phantom-deps | phantom-dep:@types/fs-extra | AI (phantom-deps): Type-only package; stable false positive for this component library. | ai |
Versions (showing 97 of 97)
| Version | Deps | Published |
|---|---|---|
| 27.3.3 | 15 / 70 | |
| 27.3.2 | 15 / 70 | |
| 27.3.1 | 15 / 70 | |
| 27.3.0 | 15 / 70 | |
| 27.2.0 | 15 / 70 | |
| 27.1.2 | 15 / 70 | |
| 27.1.1 | 15 / 70 | |
| 27.1.0 | 15 / 66 | |
| 27.0.0 | 15 / 66 | |
| 26.1.1 | 15 / 66 | |
| 26.1.0 | 15 / 66 | |
| 26.0.3 | 15 / 66 | |
| 26.0.2 | 15 / 66 | |
| 26.0.1 | 15 / 66 | |
| 26.0.0 | 15 / 66 | |
| 25.32.0 | 15 / 66 | |
| 25.31.0 | 15 / 66 | |
| 25.30.0 | 18 / 66 | |
| 25.29.0 | 18 / 66 | |
| 25.28.0 | 18 / 66 | |
| 25.27.0 | 18 / 66 | |
| 25.26.3 | 18 / 66 | |
| 25.26.2 | 18 / 66 | |
| 25.26.1 | 18 / 66 | |
| 25.26.0 | 18 / 66 | |
| 25.25.0 | 18 / 66 | |
| 25.24.0 | 18 / 66 | |
| 25.23.0 | 18 / 64 | |
| 25.22.6 | 18 / 64 | |
| 25.22.5 | 18 / 64 | |
| 25.22.4 | 18 / 64 | |
| 25.22.3 | 18 / 64 | |
| 25.22.2 | 18 / 64 | |
| 25.22.1 | 18 / 64 | |
| 25.22.0 | 18 / 64 | |
| 25.21.1 | 18 / 64 | |
| 25.21.0 | 18 / 64 | |
| 25.20.0 | 18 / 64 | |
| 25.19.4 | 18 / 64 | |
| 25.19.3 | 18 / 64 | |
| 25.19.2 | 18 / 64 | |
| 25.19.1 | 18 / 64 | |
| 25.19.0 | 18 / 64 | |
| 25.18.1 | 18 / 64 | |
| 25.18.0 | 18 / 64 | |
| 25.17.1 | 18 / 64 | |
| 25.17.0 | 18 / 64 | |
| 25.16.1 | 18 / 64 | |
| 25.16.0 | 18 / 64 | |
| 25.15.3 | 18 / 64 | |
| 25.15.2 | 18 / 64 | |
| 25.15.1 | 18 / 64 | |
| 25.15.0 | 18 / 64 | |
| 25.14.0 | 18 / 64 | |
| 25.13.2 | 18 / 64 | |
| 25.13.1 | 18 / 64 | |
| 25.13.0 | 18 / 64 | |
| 25.12.4 | 18 / 64 | |
| 25.12.3 | 18 / 64 | |
| 25.12.2 | 18 / 64 | |
| 25.12.1 | 18 / 64 | |
| 25.12.0 | 18 / 64 | |
| 25.11.0 | 18 / 64 | |
| 25.10.6 | 18 / 64 | |
| 25.10.5 | 18 / 64 | |
| 25.10.4 | 18 / 64 | |
| 25.10.3 | 18 / 64 | |
| 25.10.2 | 18 / 64 | |
| 25.10.1 | 18 / 64 | |
| 25.10.0 | 18 / 64 | |
| 25.9.2 | 18 / 64 | |
| 25.9.1 | 18 / 66 | |
| 25.9.0 | 18 / 66 | |
| 25.8.2 | 18 / 66 | |
| 25.8.1 | 18 / 66 | |
| 25.8.0 | 18 / 66 | |
| 25.7.1 | 18 / 66 | |
| 25.7.0 | 18 / 66 | |
| 25.6.0 | 18 / 66 | |
| 25.5.0 | 18 / 66 | |
| 25.4.4 | 18 / 66 | |
| 25.4.3 | 18 / 66 | |
| 25.4.2 | 18 / 66 | |
| 25.4.1 | 18 / 66 | |
| 25.4.0 | 18 / 66 | |
| 25.3.0 | 18 / 66 | |
| 25.2.0 | 18 / 66 | |
| 25.1.3 | 18 / 66 | |
| 25.1.2 | 18 / 66 | |
| 25.1.1 | 18 / 66 | |
| 25.1.0 | 18 / 66 | |
| 25.0.5 | 18 / 66 | |
| 25.0.4 | 18 / 66 | |
| 25.0.3 | 18 / 66 | |
| 25.0.2 | 18 / 66 | |
| 25.0.1 | 18 / 66 | |
| 25.0.0 | 18 / 66 |
v27.3.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.3.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.3.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.3.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.2.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.1.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.1.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: smg-automotive-engineering.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v27.0.0
2 findings[Reject — re-review on republish] (prior reject: AI (install-scripts): Postinstall runs npx chakra typegen on consumer machines — new addition, not appropriate for a UI component library.) Script: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.1.1
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.1.0
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.0.3
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.0.2
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.0.1
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v26.0.0
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.32.0
2 findingsScript: npm run typegen
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.26.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.26.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.24.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.23.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.22.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.21.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.20.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.19.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.19.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.19.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.19.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.19.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.18.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.17.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.15.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.15.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.15.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.13.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.13.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.13.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.12.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.12.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.12.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.12.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.10.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.10.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.10.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.10.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.10.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.10.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.9.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.8.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.4.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.1.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v25.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v25.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.