← Home

@sps-woodland/rich-text-editor

SPS Design System rich text editor component

51
Versions
UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

spsc_cafmacybuanjimthedevknedevspschrisndev

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:lib/index-CrCZYukE.js AI (source-diff): Vite build output; readable imports confirm legitimate bundled React component, not obfuscation. ai
source-diff obfuscated-file:lib/index-mwtWTZtq.js AI (source-diff): Vite-hashed bundle output; sample shows plain React component code, not obfuscation. Pattern recurs across versions of this build-tool-based package. ai
source-diff obfuscated-file:lib/index-C9vi4hTb.js AI (source-diff): Vite build output; minified but not obfuscated — readable imports visible at file head. Stable pattern for this package. ai
source-diff obfuscated-file:lib/index-CWfrZLjh.js AI (source-diff): Standard Vite build output; long lines are minified bundle, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/index-Dh9i9B_l.js AI (source-diff): Vite-minified bundle for a React component; consistent pattern across this package's versions. ai
source-diff obfuscated-file:lib/index-C5KKNt05.js AI (source-diff): Vite build output; minified but readable React component code from the SPS woodland design system. ai
source-diff obfuscated-file:lib/index-_7vZbbBA.js AI (source-diff): Vite build output; long lines are minified bundle chunks, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/index-CuDgjmya.js AI (source-diff): Vite-bundled output with readable imports; minified line length, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/index-C5PJE3OS.js AI (source-diff): Standard Vite minified bundle output; readable imports confirm legitimate build artifact, not obfuscation. ai
source-diff obfuscated-file:lib/index-DEoJY9vf.js AI (source-diff): Vite build output; minified but readable imports confirm legitimate bundling pattern for this design system package. ai
source-diff obfuscated-file:lib/index-GQbLxiWp.js AI (source-diff): Standard Vite build output; minified but readable imports confirm legitimate bundling pattern for this package. ai
source-diff obfuscated-file:lib/index-tCCJeGu9.js AI (source-diff): Vite build output for a React component; minified but readable imports confirm legitimate bundled source. ai
phantom-deps phantom-dep:@spscommerce/i18n AI (phantom-deps): Internal i18n dependency; used in config, not direct imports. ai
phantom-deps phantom-dep:unist-util-visit AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. ai
phantom-deps phantom-dep:remark-stringify AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. ai
phantom-deps phantom-dep:rehype-stringify AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. ai
phantom-deps phantom-dep:rehype-sanitize AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. ai
phantom-deps phantom-dep:remark-rehype AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. ai
phantom-deps phantom-dep:rehype-remark AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. ai
phantom-deps phantom-dep:rehype-parse AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. ai
phantom-deps phantom-dep:remark-parse AI (phantom-deps): Remark/rehype pipeline dependencies; used in config, not direct imports. ai

Versions (showing 51 of 96)

View all versions
Version Deps Published
8.46.7 10 / 9
8.46.6 10 / 9
8.46.5 10 / 9
8.46.4 10 / 9
8.46.3 10 / 9
8.46.2 10 / 9
8.46.1 10 / 9
8.46.0 10 / 9
8.45.8 10 / 9
8.45.7 10 / 9
8.45.6 10 / 9
8.45.5 10 / 9
8.45.4 10 / 9
8.45.3 10 / 9
8.45.2 10 / 9
8.45.1 10 / 9
8.45.0 10 / 9
8.44.1 10 / 9
8.44.0 10 / 9
8.43.1 10 / 9
8.43.0 10 / 9
8.42.7 10 / 9
8.42.6 10 / 9
8.42.5 10 / 9
8.42.4 10 / 9
8.42.3 10 / 9
8.42.2 10 / 9
8.42.1 10 / 9
8.42.0 10 / 9
8.41.4 10 / 9
8.41.3 10 / 9
8.41.2 10 / 9
8.41.1 10 / 9
8.41.0 10 / 9
8.40.0 10 / 9
8.39.0 10 / 9
8.38.2 10 / 9
8.38.1 10 / 9
8.38.0 10 / 9
8.37.8 10 / 9
8.37.7 10 / 9
8.37.6 10 / 9
8.37.5 10 / 9
8.37.4 10 / 9
8.37.3 10 / 9
8.37.2 10 / 9
8.37.1 10 / 9
8.37.0 10 / 9
8.36.0 10 / 9
8.35.6 10 / 9
8.35.5 10 / 9

v8.46.7

2 findings
HIGH New obfuscated file: lib/index-CWfrZLjh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.6

2 findings
HIGH New obfuscated file: lib/index-mwtWTZtq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.5

2 findings
HIGH New obfuscated file: lib/index-Dh9i9B_l.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.4

2 findings
HIGH New obfuscated file: lib/index-DEoJY9vf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.3

2 findings
HIGH New obfuscated file: lib/index-C9vi4hTb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.2

2 findings
HIGH New obfuscated file: lib/index-C5KKNt05.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.1

2 findings
HIGH New obfuscated file: lib/index-_7vZbbBA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.46.0

2 findings
HIGH New obfuscated file: lib/index-C5PJE3OS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.8

2 findings
HIGH New obfuscated file: lib/index-CrCZYukE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.7

2 findings
HIGH New obfuscated file: lib/index-tCCJeGu9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.6

2 findings
HIGH New obfuscated file: lib/index-GQbLxiWp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.5

2 findings
HIGH New obfuscated file: lib/index-CuDgjmya.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.45.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.45.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.44.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.44.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.43.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.43.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.42.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.41.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.41.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.41.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.41.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.41.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.40.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.39.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.38.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.38.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.38.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.37.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.37.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.37.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.37.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.37.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.37.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.36.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.35.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.35.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.