← Home

@spark-ui/components

Spark (Leboncoin design system) components.

100
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

soykjepowerplexalex.acd02spark-web-admin

Keywords

@spark-uireactcomponentaccessibleaccessibilitywai-ariaariaa11y

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/button-pb2JbL37.js AI (source-diff): Standard bundler minified output, not obfuscation. ai
source-diff obfuscated-file:dist/popover-DK2-MWUF.js AI (source-diff): Standard bundler minified output, not obfuscation. ai
source-diff obfuscated-file:dist/input-Bmkrsnjd.js AI (source-diff): Standard bundler minified output, not obfuscation. ai
source-diff obfuscated-file:dist/form-field-B38U0zp8.js AI (source-diff): Standard bundler minified output, not obfuscation. ai
source-diff obfuscated-file:dist/checkbox-Cbewcw6G.js AI (source-diff): Standard bundler minified output, not obfuscation. ai
source-diff obfuscated-file:dist/button-jlscsCw0.js AI (source-diff): Vite-minified Button component with shipped sourcemap; no eval/_0x/packer. Standard build output. ai
source-diff obfuscated-file:dist/popover-qoueDrzR.js AI (source-diff): Vite-minified Popover component with shipped sourcemap; no eval/_0x/packer. Standard build output. ai
source-diff obfuscated-file:dist/input-DIGSkxbh.js AI (source-diff): Standard Vite minified bundle for a React UI component; not obfuscated malware. ai
source-diff obfuscated-file:dist/popover-q0MDNefk.js AI (source-diff): Standard Vite CJS bundle output; content shows normal React popover component patterns using radix-ui. ai
source-diff obfuscated-file:dist/input-CZGLUZjM.js AI (source-diff): Standard Vite CJS bundle output; content shows normal React input component patterns. ai
source-diff obfuscated-file:dist/popover-Daknmg_Z.js AI (source-diff): Standard Vite CJS bundle output; readable React component code. ai
source-diff obfuscated-file:dist/button-Tv2N8_24.js AI (source-diff): Standard Vite CJS bundle output for a React UI library; readable component code, not malicious obfuscation. ai
source-diff obfuscated-file:dist/checkbox-hVGRiWC_.js AI (source-diff): Same Vite bundle pattern; content is standard checkbox component logic. ai
source-diff obfuscated-file:dist/popover-CWZCAwhW.js AI (source-diff): Same Vite bundle pattern; content is standard popover component logic. ai
source-diff obfuscated-file:dist/input-BSCMbnO4.js AI (source-diff): Same Vite bundle pattern; content is standard input component logic. ai
source-diff obfuscated-file:dist/form-field-BCqHBvWN.js AI (source-diff): Same Vite bundle pattern; content is standard form-field component logic. ai
source-diff obfuscated-file:dist/button-pz6WB_vb.js AI (source-diff): Vite-bundled CJS output for a React UI library; long lines are minified but readable component code. ai
phantom-deps phantom-dep:@react-stately/toast AI (phantom-deps): Same as @react-aria/toast; config-only reference, stable false positive. ai
phantom-deps phantom-dep:@react-aria/toast AI (phantom-deps): Toast component dep referenced in config/type files; stable false positive for this package. ai
source-diff obfuscated-file:dist/form-field-Bu_0E9tb.js AI (source-diff): Vite-bundled CJS output; readable React component logic, no malicious patterns. ai
source-diff obfuscated-file:dist/button-BTDRzvpB.js AI (source-diff): Vite-bundled CJS output; readable React component logic, no malicious patterns. ai
source-diff obfuscated-file:dist/input-DNr40G2Z.js AI (source-diff): Vite-bundled CJS output; readable React component logic, no malicious patterns. ai
source-diff obfuscated-file:dist/popover-GOovJ27J.js AI (source-diff): Vite-bundled CJS output; readable React component logic, no malicious patterns. ai
source-diff obfuscated-file:dist/progress-rJZcPJsZ.js AI (source-diff): Vite-bundled CJS output; readable React component logic, no malicious patterns. ai
source-diff large-new-source-files AI (source-diff): Large component library with Vite chunk splitting; many small files expected across versions. ai
source-diff obfuscated-file:dist/input-DaShg4eE.js AI (source-diff): Vite-bundled CJS output; readable React/Tailwind component logic, no obfuscation. ai
source-diff obfuscated-file:dist/form-field-CYGgse45.js AI (source-diff): Vite build output for a React component library; minified but not obfuscated, consistent with all prior versions. ai
source-diff obfuscated-file:dist/input-Cx5cfgE8.js AI (source-diff): Vite-bundled CJS output; readable React component code, not obfuscation. ai
source-diff obfuscated-file:dist/form-field-Du1Ebx6v.js AI (source-diff): Vite-bundled CJS output; readable React component code, not obfuscation. ai
source-diff obfuscated-file:dist/Button-B6rA3-e5.js AI (source-diff): Minified but fully readable React/CVA component bundle; not obfuscated malware. tsup produces hashed chunk filenames by design. ai
source-diff obfuscated-file:dist/button-B-sMnDc_.js AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. ai
source-diff obfuscated-file:dist/checkbox-DjwbAH09.js AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. ai
source-diff obfuscated-file:dist/progress-BjqJSRnK.js AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. ai
source-diff obfuscated-file:dist/popover-CrKp_TKk.js AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. ai
source-diff obfuscated-file:dist/input-BUSYZ_VO.js AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. ai
source-diff obfuscated-file:dist/table/index.js AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. ai
source-diff obfuscated-file:dist/form-field-81wzFxM0.js AI (source-diff): Standard Vite/Rollup minified output for a React component library; not obfuscation. ai
source-diff obfuscated-file:dist/Button-FZceRWG2.js AI (source-diff): Standard Vite build output for a React UI component; minified but fully readable and benign. ai
source-diff obfuscated-file:dist/segmented-control/index.js AI (source-diff): Standard Vite build output for a React UI component; minified but fully readable and benign. ai
source-diff obfuscated-file:dist/circular-meter/index.js AI (source-diff): Standard minified CJS bundle output from vite/tsup build; no obfuscation or malicious payload present. ai
source-diff obfuscated-file:dist/button-3F9Xrf4E.js AI (source-diff): Standard Vite/Rollup minified bundle for a React UI library; content is readable component code, not malicious obfuscation. ai
source-diff obfuscated-file:dist/popover-ayPbAw59.js AI (source-diff): Standard Vite/Rollup minified bundle; content is readable React popover component code. ai
source-diff obfuscated-file:dist/menu/index.js AI (source-diff): Standard Vite/Rollup minified bundle; content is readable React menu component code. ai
provenance no-provenance AI (provenance): Established design system package; provenance absence is consistent across all 245 versions and not a risk signal here. ai
phantom-deps phantom-dep:motion AI (phantom-deps): Component library bundle; motion is a declared runtime dep likely consumed via re-exports rather than direct imports. ai
phantom-deps phantom-dep:react-aria-components AI (phantom-deps): Declared runtime dep in a component library; indirect usage via bundled exports is expected. ai

Versions (showing 100 of 113)

Version Deps Published
17.15.6 13 / 1
17.15.5 13 / 1
17.15.4 13 / 1
17.15.3 13 / 1
17.15.2 13 / 1
17.15.1 13 / 1
17.15.0 13 / 1
17.14.4 13 / 1
17.14.3 13 / 1
17.14.2 13 / 1
17.14.1 13 / 1
17.14.0 13 / 1
17.13.2 13 / 1
17.13.1 13 / 1
17.13.0 13 / 1
17.12.0 13 / 1
17.11.3 13 / 1
17.11.2 13 / 1
17.11.1 13 / 1
17.11.0 13 / 1
17.10.4 13 / 1
17.10.3 13 / 1
17.10.2 13 / 1
17.10.1 13 / 1
17.10.0 13 / 1
17.9.3 13 / 1
17.9.2 13 / 1
17.9.1 13 / 1
17.9.0 13 / 1
17.8.0 13 / 1
17.7.0 13 / 1
17.6.1 13 / 1
17.6.0 13 / 1
17.5.7 13 / 1
17.5.6 13 / 1
17.5.5 16 / 1
17.5.4 16 / 1
17.5.3 16 / 1
17.5.2 16 / 1
17.5.1 16 / 1
17.5.0 16 / 1
17.4.2 16 / 1
17.4.1 18 / 1
17.4.0 18 / 1
17.3.2 18 / 1
17.3.1 18 / 1
17.3.0 18 / 1
17.2.5 17 / 1
17.2.4 17 / 1
17.2.3 17 / 1
17.2.2 17 / 1
17.2.1 17 / 1
17.2.0 17 / 1
17.1.1 17 / 1
17.1.0 17 / 1
17.0.1 17 / 1
17.0.0 17 / 1
16.2.3 17 / 1
16.2.2 17 / 1
16.2.1 17 / 1
16.2.0 17 / 1
16.1.0 17 / 1
16.0.3 16 / 1
16.0.2 16 / 1
16.0.1 16 / 1
16.0.0 16 / 1
15.1.0 16 / 1
15.0.0 16 / 1
14.1.2 16 / 1
14.1.1 16 / 1
14.1.0 16 / 1
14.0.0 16 / 1
13.2.0 16 / 1
13.1.5 16 / 1
13.1.4 16 / 1
13.1.3 16 / 1
13.1.2 16 / 1
13.1.1 16 / 1
13.1.0 16 / 1
13.0.7 16 / 1
13.0.6 16 / 1
13.0.5 16 / 1
13.0.4 16 / 1
13.0.3 16 / 1
13.0.2 16 / 1
13.0.1 16 / 1
12.2.0 16 / 1
12.1.2 16 / 1
12.1.1 16 / 1
12.1.0 16 / 1
12.0.1 16 / 1
12.0.0 16 / 1
11.7.1 16 / 1
11.7.0 16 / 1
11.6.1 16 / 1
11.6.0 16 / 1
11.5.1 16 / 1
11.5.0 16 / 1
11.4.3 16 / 1
11.4.2 16 / 1
Showing 100 of 113 Next page →

v17.15.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.15.5

6 findings
HIGH New obfuscated file: dist/button-pb2JbL37.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/checkbox-Cbewcw6G.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/form-field-B38U0zp8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/input-Bmkrsnjd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popover-DK2-MWUF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.15.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.15.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.15.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.15.1

4 findings
HIGH Publisher changed: powerplex → spark-web-admin (on 2026-06-29) provenance

This version was published by a different npm account than previous versions on 2026-06-29. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/button-jlscsCw0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popover-qoueDrzR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.15.0

3 findings
HIGH New obfuscated file: dist/button-jlscsCw0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/popover-qoueDrzR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v13.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v13.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v13.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v13.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v13.0.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v13.0.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v13.0.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v13.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v13.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v13.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v13.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v12.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v12.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v12.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v12.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v12.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v12.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.7.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.4.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.4.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.