← Home

@sps-woodland/product-bar-vertical

SPS Woodland Design System product bar vertical component

51
Versions
UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

spsc_cafmacybuanjimthedevknedevspschrisndev

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:lib/index-DyE5bG-Y.js AI (source-diff): Vite build output for a React component library; long lines are minified bundle, not obfuscation. ai
source-diff obfuscated-file:lib/index-Bz3KfC4N.js AI (source-diff): Vite build output for a React component; readable imports and hooks visible in sample, not obfuscated. ai
source-diff obfuscated-file:lib/index-BWrO_L-j.js AI (source-diff): Vite build output; minified bundle is expected for this design system component package. ai
source-diff obfuscated-file:lib/index-Cm3dmWlb.js AI (source-diff): Vite-bundled output with readable React code; minification is expected for this design system component package. ai
source-diff obfuscated-file:lib/index-DH5lSYIi.js AI (source-diff): Vite build output with hashed filename; code is readable minified React, not obfuscated. Stable pattern for this design system package. ai
source-diff obfuscated-file:lib/index-CLLeAQaU.js AI (source-diff): Vite build output with readable React code; minified variable names are standard for this package's build toolchain. ai
phantom-deps phantom-dep:@react-aria/link AI (phantom-deps): @react-aria/link is a declared runtime dep likely used transitively via bundled code; stable false positive for this package. ai
source-diff obfuscated-file:lib/index-BlXY1GrK.js AI (source-diff): Vite-bundled output with readable React imports; not obfuscated, just minified build artifact. ai
source-diff source-size-tripled AI (source-diff): Size increase reflects bundling of additional SPS Woodland components, consistent with design system build pattern. ai
source-diff obfuscated-file:lib/index-CXQIliqx.js AI (source-diff): File is Vite-bundled output with readable React code; minification is expected for this component library. ai

Versions (showing 51 of 96)

View all versions
Version Deps Published
8.46.7 2 / 7
8.46.6 2 / 7
8.46.5 2 / 7
8.46.4 2 / 7
8.46.3 2 / 7
8.46.2 2 / 7
8.46.1 2 / 7
8.46.0 2 / 7
8.45.8 1 / 7
8.45.7 1 / 7
8.45.6 1 / 7
8.45.5 1 / 7
8.45.4 1 / 7
8.45.3 1 / 7
8.45.2 1 / 7
8.45.1 1 / 7
8.45.0 1 / 7
8.44.1 1 / 7
8.44.0 1 / 7
8.43.1 1 / 7
8.43.0 1 / 7
8.42.7 1 / 7
8.42.6 1 / 7
8.42.5 1 / 7
8.42.4 1 / 7
8.42.3 1 / 7
8.42.2 1 / 7
8.42.1 1 / 7
8.42.0 1 / 7
8.41.4 1 / 7
8.41.3 1 / 7
8.41.2 1 / 7
8.41.1 1 / 7
8.41.0 1 / 7
8.40.0 1 / 7
8.39.0 1 / 7
8.38.2 1 / 7
8.38.1 1 / 7
8.38.0 1 / 7
8.37.8 1 / 7
8.37.7 1 / 7
8.37.6 1 / 7
8.37.5 1 / 7
8.37.4 1 / 7
8.37.3 1 / 7
8.37.2 1 / 7
8.37.1 1 / 7
8.37.0 1 / 7
8.36.0 1 / 7
8.35.6 1 / 7
8.35.5 1 / 7

v8.46.7

2 findings
HIGH New obfuscated file: lib/index-DyE5bG-Y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.6

2 findings
HIGH New obfuscated file: lib/index-Cm3dmWlb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.5

2 findings
HIGH New obfuscated file: lib/index-BWrO_L-j.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.4

2 findings
HIGH New obfuscated file: lib/index-DH5lSYIi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.3

2 findings
HIGH New obfuscated file: lib/index-Bz3KfC4N.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.2

2 findings
HIGH New obfuscated file: lib/index-CLLeAQaU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.1

2 findings
HIGH New obfuscated file: lib/index-BlXY1GrK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.0

2 findings
HIGH New obfuscated file: lib/index-CXQIliqx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.45.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.44.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.44.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.43.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.43.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.41.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.41.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.41.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.41.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.41.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.40.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.39.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.38.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.38.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.38.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.36.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.35.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.35.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.