@stytch/react
Stytch's official React Library
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/cjs-dev/shadcn-_aqkqkH3.js | AI (source-diff): Minified bundled output, not true obfuscation; standard rollup build. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Result of bundling new UI deps, not injected payload. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New shadcn UI bundle files, legitimate dependency growth. | ai | |
| source-diff | obfuscated-file:dist/cjs/shadcn-DhFLwrw_.js | AI (source-diff): Minified bundled output, not true obfuscation; standard rollup build. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/shadcn-BDx_oy_4.js | AI (source-diff): Minified bundled build output (rollup), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/shadcn-CLGNjm4Z.js | AI (source-diff): Minified bundled build output (rollup), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/shadcn-dywCoz6I.js | AI (source-diff): Rollup bundle output, not obfuscation; readable code with comments. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/shadcn-a7wEotQG.js | AI (source-diff): Rollup bundle output, not obfuscation; readable code with comments. | ai | |
| provenance | publisher-changed | AI (provenance): CI-shaped publisher change (ci-stytch to GitHub Actions), typical automation transition. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/shadcn-BZDGkwFh.js | AI (source-diff): Rollup-bundled minified output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/shadcn-Du-ZeW8t.js | AI (source-diff): Rollup-bundled minified output, not true obfuscation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): twilio-supply-chain addition consistent with Stytch/Twilio acquisition; legitimate org-level CI account. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/shadcn-D-YWbhvR.js | AI (source-diff): Standard Rollup CJS bundle output; long lines are minified but readable React code with source maps present. | ai | |
| source-diff | obfuscated-file:dist/cjs/shadcn-WJP_TN8o.js | AI (source-diff): Standard Rollup CJS bundle output; same pattern as dev variant, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/types/createAuthUrlHandler-mkYEIbAI.d.ts | AI (source-diff): TypeScript declaration file with long union types; not obfuscated, just large generated .d.ts. | ai | |
| source-diff | obfuscated-file:dist/types/ui-tK4kfOEk.d.ts | AI (source-diff): Large generated TypeScript declaration file; readable type definitions, not obfuscated. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): jack-stytch removal paired with twilio-supply-chain addition; expected org transition, not a takeover. | ai | |
| source-diff | obfuscated-file:dist/cjs/adminPortal/index.cjs | AI (source-diff): Bundled CJS output with long lines; standard build artifact for this package. | ai | |
| source-diff | net-exec-file:dist/cjs-dev/adminPortal/index.cjs | AI (source-diff): Auth SDK bundle naturally contains network calls and dynamic patterns. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/adminPortal/index.cjs | AI (source-diff): Bundled CJS output with long lines; standard build artifact for this package. | ai | |
| source-diff | obfuscated-file:dist/cjs/shadcn-DL3WnEgS.js | AI (source-diff): Bundled CJS output; long lines from build tooling, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/shadcn-D6hbC88a.js | AI (source-diff): Bundled CJS output; long lines from build tooling, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/cjs/adminPortal/index.cjs | AI (source-diff): Auth SDK bundle naturally contains network calls and dynamic patterns. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/shadcn-DuV5DMFG.js | AI (source-diff): Standard rollup-minified CJS dev bundle; same pattern as production build. | ai | |
| source-diff | obfuscated-file:dist/cjs/shadcn-B9lEGRrj.js | AI (source-diff): Standard rollup-minified CJS bundle output; readable source comments visible in sample. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 20.0.10 | 0 / 16 | |
| 20.0.9 | 0 / 16 | |
| 20.0.8 | 0 / 16 | |
| 20.0.7 | 0 / 16 | |
| 20.0.6 | 0 / 16 | |
| 20.0.5 | 0 / 16 | |
| 20.0.4 | 0 / 16 | |
| 20.0.3 | 0 / 16 | |
| 20.0.2 | 0 / 16 | |
| 20.0.1 | 0 / 16 | |
| 20.0.0 | 0 / 16 | |
| 19.18.1 | 0 / 20 | |
| 19.18.0 | 0 / 20 | |
| 19.17.0 | 0 / 20 | |
| 19.16.0 | 0 / 20 | |
| 19.15.2 | 0 / 20 | |
| 19.15.1 | 0 / 20 |
v20.0.5
2 findingsThis version was published by a different npm account than previous versions on 2026-03-19. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20.0.4
4 findingsThis version was published by a different npm account than previous versions on 2026-03-05. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20.0.3
4 findingsThis version was published by a different npm account than previous versions on 2026-02-27. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20.0.2
4 findingsThis version was published by a different npm account than previous versions on 2026-02-13. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20.0.1
4 findingsThis version was published by a different npm account than previous versions on 2026-02-11. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v20.0.0
4 findingsThis version was published by a different npm account than previous versions on 2026-02-11. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.