@stigmer/react
React provider and client hook for the Stigmer platform SDK
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:agent-instance/CreateAgentInstanceDialog.js | AI (source-diff): Readable JSX component with named exports and JSDoc; long lines are bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:agent-instance/AgentInstanceDetailPanel.js | AI (source-diff): Readable JSX component with named exports and JSDoc; long lines are bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:workflow/instance/CreateWorkflowInstanceDialog.js | AI (source-diff): Same pattern — long lines from inline Tailwind classes in readable JSX. Stable false positive. | ai | |
| source-diff | obfuscated-file:workflow/inspector/forms/AgentCallForm.js | AI (source-diff): Long lines are Tailwind CSS class strings in readable JSX, not obfuscation. Stable false positive for this package. | ai | |
| source-diff | obfuscated-file:workflow/CanvasTaskNode.js | AI (source-diff): Long lines are JSX transpiler output (jsx-runtime calls), not obfuscation. Stable pattern for this build pipeline. | ai | |
| source-diff | obfuscated-file:mcp-server/steps/EnvironmentAuthStep.js | AI (source-diff): Long lines are JSX transpiler output with readable comments and logic, not obfuscation. | ai | |
| source-diff | obfuscated-file:agent/steps/IdentityStep.js | AI (source-diff): Long lines are JSX transpiler output with readable comments and logic, not obfuscation. | ai | |
| source-diff | obfuscated-file:mcp-server/steps/IdentityTransportStep.js | AI (source-diff): Long lines are JSX transpiler output with readable comments and logic, not obfuscation. | ai | |
| source-diff | obfuscated-file:library/ImportResourceDialog.js | AI (source-diff): Long lines are JSX transpiler output with readable comments and logic, not obfuscation. | ai | |
| source-diff | obfuscated-file:inline-edit/InlineEditKeyValue.js | AI (source-diff): Long lines are JSX transpiler output with readable comments and logic, not obfuscation. | ai | |
| source-diff | obfuscated-file:platform-client/CreatePlatformClientForm.js | AI (source-diff): Long lines are compiled/bundled React JSX output with clear readable structure, JSDoc, and named exports — not obfuscation. Stable false positive for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:identity-provider/CreateIdentityProviderForm.js | AI (source-diff): Long lines are compiled/bundled React JSX output with clear readable structure, JSDoc, and named exports — not obfuscation. Stable false positive for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:platform-client/PlatformClientDetailPanel.js | AI (source-diff): Long lines are compiled/bundled React JSX output with clear readable structure, JSDoc, and named exports — not obfuscation. Stable false positive for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:oauth-app/OAuthAppDetailPanel.js | AI (source-diff): Long lines are bundler/transpiler output for a React component library, not obfuscation. Content is semantically coherent JSX with readable logic and JSDoc. | ai | |
| source-diff | obfuscated-file:mcp-server/OAuthAppForm.js | AI (source-diff): Long lines are bundler/transpiler output for a React component library, not obfuscation. Content is semantically coherent JSX with readable logic and JSDoc. | ai | |
| source-diff | obfuscated-file:oauth-app/CreateOAuthAppForm.js | AI (source-diff): Long lines are bundler/transpiler output for a React component library, not obfuscation. Content is semantically coherent JSX with readable logic and JSDoc. | ai | |
| source-diff | obfuscated-file:identity-provider/IdentityProviderDetailPanel.js | AI (source-diff): File is minified compiled output from a TypeScript/TSX source, not obfuscated malware. Sample shows readable React component code with JSDoc and standard patterns. | ai | |
| source-diff | obfuscated-file:organization/OrgProfilePanel.js | AI (source-diff): File is minified compiled output from a TypeScript/TSX source, not obfuscated malware. Sample shows readable React component code with standard hooks and patterns. | ai | |
| provenance | no-provenance | AI (provenance): Lack of provenance is common (~88% of npm packages); no other risk signals present to elevate this concern for this package. | ai |
Versions (showing 51 of 107)
| Version | Deps | Published |
|---|---|---|
| 3.1.3 | 13 / 0 | |
| 3.1.2 | 13 / 0 | |
| 3.1.1 | 13 / 0 | |
| 3.1.0 | 13 / 0 | |
| 3.0.8 | 10 / 0 | |
| 3.0.7 | 10 / 0 | |
| 3.0.6 | 10 / 0 | |
| 3.0.5 | 10 / 0 | |
| 3.0.4 | 10 / 0 | |
| 3.0.3 | 10 / 0 | |
| 3.0.2 | 10 / 0 | |
| 3.0.1 | 10 / 0 | |
| 3.0.0 | 10 / 0 | |
| 2.0.1 | 10 / 0 | |
| 2.0.0 | 10 / 0 | |
| 1.0.4 | 9 / 0 | |
| 1.0.3 | 9 / 0 | |
| 1.0.2 | 9 / 0 | |
| 1.0.1 | 9 / 0 | |
| 1.0.0 | 9 / 0 | |
| 0.5.1 | 8 / 0 | |
| 0.5.0 | 8 / 0 | |
| 0.4.8 | 5 / 0 | |
| 0.4.7 | 5 / 0 | |
| 0.4.6 | 5 / 0 | |
| 0.4.5 | 5 / 0 | |
| 0.4.4 | 5 / 0 | |
| 0.4.3 | 5 / 0 | |
| 0.4.2 | 5 / 0 | |
| 0.4.1 | 5 / 0 | |
| 0.4.0 | 5 / 0 | |
| 0.3.4 | 4 / 0 | |
| 0.3.3 | 4 / 0 | |
| 0.3.2 | 4 / 0 | |
| 0.3.1 | 4 / 0 | |
| 0.3.0 | 4 / 0 | |
| 0.2.3 | 4 / 0 | |
| 0.2.2 | 4 / 0 | |
| 0.2.1 | 4 / 0 | |
| 0.2.0 | 4 / 0 | |
| 0.1.2 | 4 / 0 | |
| 0.1.1 | 4 / 0 | |
| 0.1.0 | 4 / 0 | |
| 0.0.101 | 4 / 0 | |
| 0.0.100 | 4 / 0 | |
| 0.0.99 | 4 / 0 | |
| 0.0.98 | 4 / 0 | |
| 0.0.97 | 4 / 0 | |
| 0.0.96 | 4 / 0 | |
| 0.0.95 | 4 / 0 | |
| 0.0.94 | 4 / 0 |
v3.1.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.