@spark-ui/components
Spark (Leboncoin design system) components.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/button-pb2JbL37.js | AI (source-diff): Standard bundler minified output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/popover-DK2-MWUF.js | AI (source-diff): Standard bundler minified output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/input-Bmkrsnjd.js | AI (source-diff): Standard bundler minified output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/form-field-B38U0zp8.js | AI (source-diff): Standard bundler minified output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/checkbox-Cbewcw6G.js | AI (source-diff): Standard bundler minified output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/button-jlscsCw0.js | AI (source-diff): Vite-minified Button component with shipped sourcemap; no eval/_0x/packer. Standard build output. | ai | |
| source-diff | obfuscated-file:dist/popover-qoueDrzR.js | AI (source-diff): Vite-minified Popover component with shipped sourcemap; no eval/_0x/packer. Standard build output. | ai | |
| source-diff | obfuscated-file:dist/input-DIGSkxbh.js | AI (source-diff): Standard Vite minified bundle for a React UI component; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/popover-q0MDNefk.js | AI (source-diff): Standard Vite CJS bundle output; content shows normal React popover component patterns using radix-ui. | ai | |
| source-diff | obfuscated-file:dist/input-CZGLUZjM.js | AI (source-diff): Standard Vite CJS bundle output; content shows normal React input component patterns. | ai | |
| source-diff | obfuscated-file:dist/popover-Daknmg_Z.js | AI (source-diff): Standard Vite CJS bundle output; readable React component code. | ai | |
| source-diff | obfuscated-file:dist/button-Tv2N8_24.js | AI (source-diff): Standard Vite CJS bundle output for a React UI library; readable component code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/checkbox-hVGRiWC_.js | AI (source-diff): Same Vite bundle pattern; content is standard checkbox component logic. | ai | |
| source-diff | obfuscated-file:dist/popover-CWZCAwhW.js | AI (source-diff): Same Vite bundle pattern; content is standard popover component logic. | ai | |
| source-diff | obfuscated-file:dist/input-BSCMbnO4.js | AI (source-diff): Same Vite bundle pattern; content is standard input component logic. | ai | |
| source-diff | obfuscated-file:dist/form-field-BCqHBvWN.js | AI (source-diff): Same Vite bundle pattern; content is standard form-field component logic. | ai | |
| source-diff | obfuscated-file:dist/button-pz6WB_vb.js | AI (source-diff): Vite-bundled CJS output for a React UI library; long lines are minified but readable component code. | ai | |
| phantom-deps | phantom-dep:@react-stately/toast | AI (phantom-deps): Same as @react-aria/toast; config-only reference, stable false positive. | ai | |
| phantom-deps | phantom-dep:@react-aria/toast | AI (phantom-deps): Toast component dep referenced in config/type files; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/form-field-Bu_0E9tb.js | AI (source-diff): Vite-bundled CJS output; readable React component logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/button-BTDRzvpB.js | AI (source-diff): Vite-bundled CJS output; readable React component logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/input-DNr40G2Z.js | AI (source-diff): Vite-bundled CJS output; readable React component logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/popover-GOovJ27J.js | AI (source-diff): Vite-bundled CJS output; readable React component logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/progress-rJZcPJsZ.js | AI (source-diff): Vite-bundled CJS output; readable React component logic, no malicious patterns. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large component library with Vite chunk splitting; many small files expected across versions. | ai | |
| source-diff | obfuscated-file:dist/input-DaShg4eE.js | AI (source-diff): Vite-bundled CJS output; readable React/Tailwind component logic, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/form-field-CYGgse45.js | AI (source-diff): Vite build output for a React component library; minified but not obfuscated, consistent with all prior versions. | ai | |
| source-diff | obfuscated-file:dist/input-Cx5cfgE8.js | AI (source-diff): Vite-bundled CJS output; readable React component code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/form-field-Du1Ebx6v.js | AI (source-diff): Vite-bundled CJS output; readable React component code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Button-B6rA3-e5.js | AI (source-diff): Minified but fully readable React/CVA component bundle; not obfuscated malware. tsup produces hashed chunk filenames by design. | ai | |
| source-diff | obfuscated-file:dist/button-B-sMnDc_.js | AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/checkbox-DjwbAH09.js | AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/progress-BjqJSRnK.js | AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/popover-CrKp_TKk.js | AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/input-BUSYZ_VO.js | AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/table/index.js | AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/form-field-81wzFxM0.js | AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Button-FZceRWG2.js | AI (source-diff): Standard Vite build output for a React UI component; minified but fully readable and benign. | ai | |
| source-diff | obfuscated-file:dist/segmented-control/index.js | AI (source-diff): Standard Vite build output for a React UI component; minified but fully readable and benign. | ai | |
| source-diff | obfuscated-file:dist/circular-meter/index.js | AI (source-diff): Standard minified CJS bundle output from vite/tsup build; no obfuscation or malicious payload present. | ai | |
| source-diff | obfuscated-file:dist/button-3F9Xrf4E.js | AI (source-diff): Standard Vite/Rollup minified bundle for a React UI library; content is readable component code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/popover-ayPbAw59.js | AI (source-diff): Standard Vite/Rollup minified bundle; content is readable React popover component code. | ai | |
| source-diff | obfuscated-file:dist/menu/index.js | AI (source-diff): Standard Vite/Rollup minified bundle; content is readable React menu component code. | ai | |
| provenance | no-provenance | AI (provenance): Established design system package; provenance absence is consistent across all 245 versions and not a risk signal here. | ai | |
| phantom-deps | phantom-dep:motion | AI (phantom-deps): Component library bundle; motion is a declared runtime dep likely consumed via re-exports rather than direct imports. | ai | |
| phantom-deps | phantom-dep:react-aria-components | AI (phantom-deps): Declared runtime dep in a component library; indirect usage via bundled exports is expected. | ai |
Versions (showing 51 of 113)
| Version | Deps | Published |
|---|---|---|
| 17.15.6 | 13 / 1 | |
| 17.15.5 | 13 / 1 | |
| 17.15.4 | 13 / 1 | |
| 17.15.3 | 13 / 1 | |
| 17.15.2 | 13 / 1 | |
| 17.15.1 | 13 / 1 | |
| 17.15.0 | 13 / 1 | |
| 17.14.4 | 13 / 1 | |
| 17.14.3 | 13 / 1 | |
| 17.14.2 | 13 / 1 | |
| 17.14.1 | 13 / 1 | |
| 17.14.0 | 13 / 1 | |
| 17.13.2 | 13 / 1 | |
| 17.13.1 | 13 / 1 | |
| 17.13.0 | 13 / 1 | |
| 17.12.0 | 13 / 1 | |
| 17.11.3 | 13 / 1 | |
| 17.11.2 | 13 / 1 | |
| 17.11.1 | 13 / 1 | |
| 17.11.0 | 13 / 1 | |
| 17.10.4 | 13 / 1 | |
| 17.10.3 | 13 / 1 | |
| 17.10.2 | 13 / 1 | |
| 17.10.1 | 13 / 1 | |
| 17.10.0 | 13 / 1 | |
| 17.9.3 | 13 / 1 | |
| 17.9.2 | 13 / 1 | |
| 17.9.1 | 13 / 1 | |
| 17.9.0 | 13 / 1 | |
| 17.8.0 | 13 / 1 | |
| 17.7.0 | 13 / 1 | |
| 17.6.1 | 13 / 1 | |
| 17.6.0 | 13 / 1 | |
| 17.5.7 | 13 / 1 | |
| 17.5.6 | 13 / 1 | |
| 17.5.5 | 16 / 1 | |
| 17.5.4 | 16 / 1 | |
| 17.5.3 | 16 / 1 | |
| 17.5.2 | 16 / 1 | |
| 17.5.1 | 16 / 1 | |
| 17.5.0 | 16 / 1 | |
| 17.4.2 | 16 / 1 | |
| 17.4.1 | 18 / 1 | |
| 17.4.0 | 18 / 1 | |
| 17.3.2 | 18 / 1 | |
| 17.3.1 | 18 / 1 | |
| 17.3.0 | 18 / 1 | |
| 17.2.5 | 17 / 1 | |
| 17.2.4 | 17 / 1 | |
| 17.2.3 | 17 / 1 | |
| 17.2.2 | 17 / 1 |
v17.15.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.15.5
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.15.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.15.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.15.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.15.1
4 findingsThis version was published by a different npm account than previous versions on 2026-06-29. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v17.15.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.