@sps-woodland/rich-text-editor
SPS Design System rich text editor component
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:lib/index-CrCZYukE.js | AI (source-diff): Vite build output; readable imports confirm legitimate bundled React component, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/index-mwtWTZtq.js | AI (source-diff): Vite-hashed bundle output; sample shows plain React component code, not obfuscation. Pattern recurs across versions of this build-tool-based package. | ai | |
| source-diff | obfuscated-file:lib/index-C9vi4hTb.js | AI (source-diff): Vite build output; minified but not obfuscated — readable imports visible at file head. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:lib/index-CWfrZLjh.js | AI (source-diff): Standard Vite build output; long lines are minified bundle, not obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:lib/index-Dh9i9B_l.js | AI (source-diff): Vite-minified bundle for a React component; consistent pattern across this package's versions. | ai | |
| source-diff | obfuscated-file:lib/index-C5KKNt05.js | AI (source-diff): Vite build output; minified but readable React component code from the SPS woodland design system. | ai | |
| source-diff | obfuscated-file:lib/index-_7vZbbBA.js | AI (source-diff): Vite build output; long lines are minified bundle chunks, not obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:lib/index-CuDgjmya.js | AI (source-diff): Vite-bundled output with readable imports; minified line length, not obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:lib/index-C5PJE3OS.js | AI (source-diff): Standard Vite minified bundle output; readable imports confirm legitimate build artifact, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/index-DEoJY9vf.js | AI (source-diff): Vite build output; minified but readable imports confirm legitimate bundling pattern for this design system package. | ai | |
| source-diff | obfuscated-file:lib/index-GQbLxiWp.js | AI (source-diff): Standard Vite build output; minified but readable imports confirm legitimate bundling pattern for this package. | ai | |
| source-diff | obfuscated-file:lib/index-tCCJeGu9.js | AI (source-diff): Vite build output for a React component; minified but readable imports confirm legitimate bundled source. | ai | |
| phantom-deps | phantom-dep:@spscommerce/i18n | AI (phantom-deps): Internal i18n dependency; used in config, not direct imports. | ai | |
| phantom-deps | phantom-dep:unist-util-visit | AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. | ai | |
| phantom-deps | phantom-dep:remark-stringify | AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. | ai | |
| phantom-deps | phantom-dep:rehype-stringify | AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. | ai | |
| phantom-deps | phantom-dep:rehype-sanitize | AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. | ai | |
| phantom-deps | phantom-dep:remark-rehype | AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. | ai | |
| phantom-deps | phantom-dep:rehype-remark | AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. | ai | |
| phantom-deps | phantom-dep:rehype-parse | AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. | ai | |
| phantom-deps | phantom-dep:remark-parse | AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. | ai |
Versions (showing 51 of 96)
| Version | Deps | Published |
|---|---|---|
| 8.46.7 | 10 / 9 | |
| 8.46.6 | 10 / 9 | |
| 8.46.5 | 10 / 9 | |
| 8.46.4 | 10 / 9 | |
| 8.46.3 | 10 / 9 | |
| 8.46.2 | 10 / 9 | |
| 8.46.1 | 10 / 9 | |
| 8.46.0 | 10 / 9 | |
| 8.45.8 | 10 / 9 | |
| 8.45.7 | 10 / 9 | |
| 8.45.6 | 10 / 9 | |
| 8.45.5 | 10 / 9 | |
| 8.45.4 | 10 / 9 | |
| 8.45.3 | 10 / 9 | |
| 8.45.2 | 10 / 9 | |
| 8.45.1 | 10 / 9 | |
| 8.45.0 | 10 / 9 | |
| 8.44.1 | 10 / 9 | |
| 8.44.0 | 10 / 9 | |
| 8.43.1 | 10 / 9 | |
| 8.43.0 | 10 / 9 | |
| 8.42.7 | 10 / 9 | |
| 8.42.6 | 10 / 9 | |
| 8.42.5 | 10 / 9 | |
| 8.42.4 | 10 / 9 | |
| 8.42.3 | 10 / 9 | |
| 8.42.2 | 10 / 9 | |
| 8.42.1 | 10 / 9 | |
| 8.42.0 | 10 / 9 | |
| 8.41.4 | 10 / 9 | |
| 8.41.3 | 10 / 9 | |
| 8.41.2 | 10 / 9 | |
| 8.41.1 | 10 / 9 | |
| 8.41.0 | 10 / 9 | |
| 8.40.0 | 10 / 9 | |
| 8.39.0 | 10 / 9 | |
| 8.38.2 | 10 / 9 | |
| 8.38.1 | 10 / 9 | |
| 8.38.0 | 10 / 9 | |
| 8.37.8 | 10 / 9 | |
| 8.37.7 | 10 / 9 | |
| 8.37.6 | 10 / 9 | |
| 8.37.5 | 10 / 9 | |
| 8.37.4 | 10 / 9 | |
| 8.37.3 | 10 / 9 | |
| 8.37.2 | 10 / 9 | |
| 8.37.1 | 10 / 9 | |
| 8.37.0 | 10 / 9 | |
| 8.36.0 | 10 / 9 | |
| 8.35.6 | 10 / 9 | |
| 8.35.5 | 10 / 9 |
v8.46.7
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.46.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.46.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.46.4
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.46.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.46.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.46.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.46.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.45.8
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.45.7
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.45.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.45.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.45.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.45.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.45.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.45.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.45.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.44.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.44.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.43.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.43.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.42.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.42.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.42.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.42.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.42.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.42.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.42.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.42.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.41.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.41.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.41.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.41.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.41.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.38.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.38.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.37.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.37.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.37.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.37.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.37.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.37.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.37.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.37.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.37.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.36.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.35.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.35.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.