@surrealdb/ui
The SurrealDB UI Kit defines the design system and UI primitives for use throughout all frontend projects at SurrealDB.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file-transition:dist/ui.js | AI (source-diff): Sample shows bundled CodeMirror/Mantine imports, not an actual net+exec dropper payload. | ai | |
| phantom-deps | phantom-dep:micromark-extension-frontmatter | AI (phantom-deps): Same bundling artifact as other markdown deps. | ai | |
| phantom-deps | phantom-dep:mdast-util-from-markdown | AI (phantom-deps): Same bundling artifact as other markdown deps. | ai | |
| phantom-deps | phantom-dep:hast-util-to-jsx-runtime | AI (phantom-deps): Same bundling artifact as other markdown deps. | ai | |
| phantom-deps | phantom-dep:micromark-extension-gfm | AI (phantom-deps): Same bundling artifact as other markdown deps. | ai | |
| phantom-deps | phantom-dep:mdast-util-frontmatter | AI (phantom-deps): Same bundling artifact as other markdown deps. | ai | |
| source-diff | encoded-string-file:dist/ui.js | AI (source-diff): Bundled bidi/unicode lookup tables in vite build output, not an obfuscated payload. | ai | |
| phantom-deps | phantom-dep:mdast-util-gfm | AI (phantom-deps): Used via bundled markdown pipeline; dist file has no scannable imports. | ai | |
| phantom-deps | phantom-dep:node-html-parser | AI (phantom-deps): Used indirectly via markdown/config pipeline, common pattern for this lib. | ai | |
| phantom-deps | phantom-dep:mdast-util-to-hast | AI (phantom-deps): Used indirectly via markdown processing pipeline. | ai | |
| phantom-deps | phantom-dep:unist-util-visit | AI (phantom-deps): Used indirectly via markdown processing pipeline. | ai | |
| phantom-deps | phantom-dep:github-slugger | AI (phantom-deps): Used in build/config tooling, not a security concern. | ai | |
| source-diff | obfuscated-file:dist/ui.js | AI (source-diff): Bundled Vite output with readable imports, not obfuscation. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are established CodeMirror/Fontsource packages matching UI library's markdown/font features. | ai | |
| phantom-deps | phantom-dep:@lezer/markdown | AI (phantom-deps): Lezer plugins declared as runtime deps but consumed indirectly; consistent pattern for this package. | ai | |
| phantom-deps | phantom-dep:@fontsource-variable/jetbrains-mono | AI (phantom-deps): Font packages imported via CSS/config, not JS imports; expected pattern. | ai | |
| phantom-deps | phantom-dep:@fontsource-variable/geist | AI (phantom-deps): Font packages imported via CSS/config, not JS imports; expected pattern. | ai | |
| phantom-deps | phantom-dep:@codemirror/lang-markdown | AI (phantom-deps): CodemMirror lang plugins declared as runtime deps but consumed indirectly; stable pattern. | ai | |
| provenance | no-provenance | AI (provenance): GitHub Actions CI publisher; provenance absence is common and no other risk signals present. | ai | |
| dependencies | unvetted-dep:@surrealdb/lezer | AI (dependencies): Same org scope (@surrealdb); expected internal dependency for this UI library. | ai | |
| dependencies | unvetted-dep:@lezer/json | AI (dependencies): @lezer/json is a well-known CodeMirror parser package; stable dependency for this UI library. | ai | |
| phantom-deps | phantom-dep:@lezer/highlight | AI (phantom-deps): Referenced in config files for CodeMirror integration; stable false positive for this package. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped @surrealdb/ui package; Levenshtein match to short names is noise, not impersonation. | ai | |
| phantom-deps | phantom-dep:@replit/codemirror-indentation-markers | AI (phantom-deps): CodeMirror plugin loaded via config; standard pattern for this library. | ai | |
| phantom-deps | phantom-dep:@codemirror/legacy-modes | AI (phantom-deps): CodeMirror legacy modes loaded via config; standard pattern for this library. | ai | |
| phantom-deps | phantom-dep:vite-tsconfig-paths | AI (phantom-deps): Build-time Vite plugin referenced in vite config; expected phantom-dep pattern. | ai | |
| phantom-deps | phantom-dep:@lezer/javascript | AI (phantom-deps): Lezer language parser loaded via config; standard CodeMirror pattern. | ai | |
| phantom-deps | phantom-dep:@surrealdb/lezer | AI (phantom-deps): Same-org SurrealDB lezer grammar; referenced in build config, not a phantom risk. | ai | |
| phantom-deps | phantom-dep:@lezer/python | AI (phantom-deps): Lezer language parser loaded via config; standard CodeMirror pattern. | ai | |
| phantom-deps | phantom-dep:@lezer/common | AI (phantom-deps): Lezer language parser loaded via config; standard CodeMirror pattern. | ai | |
| phantom-deps | phantom-dep:@lezer/yaml | AI (phantom-deps): Lezer language parser loaded via config; standard CodeMirror pattern. | ai | |
| phantom-deps | phantom-dep:@lezer/rust | AI (phantom-deps): Lezer language parser loaded via config; standard CodeMirror pattern. | ai | |
| phantom-deps | phantom-dep:@lezer/json | AI (phantom-deps): Lezer language parser loaded via config; standard CodeMirror pattern. | ai | |
| phantom-deps | phantom-dep:@lezer/html | AI (phantom-deps): Lezer language parser loaded via config; standard CodeMirror pattern. | ai | |
| phantom-deps | phantom-dep:@lezer/php | AI (phantom-deps): Lezer language parser loaded via config; standard CodeMirror pattern. | ai | |
| phantom-deps | phantom-dep:@lezer/go | AI (phantom-deps): Lezer language parser loaded via config; standard CodeMirror pattern. | ai | |
| phantom-deps | phantom-dep:acorn | AI (phantom-deps): CodeMirror/lezer ecosystem deps referenced in build config; standard pattern for this type of library. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @surrealdb/ui package; Levenshtein match to short names is noise, not impersonation. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @surrealdb/ui package; Levenshtein match to short names is noise, not impersonation. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped @surrealdb/ui package; Levenshtein match to short names is noise, not impersonation. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped @surrealdb/ui package; Levenshtein match to short names is noise, not impersonation. | ai |
Versions (showing 100 of 101)
| Version | Deps | Published |
|---|---|---|
| 1.2.13 | 21 / 33 | |
| 1.2.12 | 20 / 31 | |
| 1.2.11 | 20 / 30 | |
| 1.2.10 | 20 / 30 | |
| 1.2.9 | 20 / 30 | |
| 1.2.8 | 20 / 30 | |
| 1.2.7 | 20 / 30 | |
| 1.2.6 | 20 / 30 | |
| 1.2.5 | 20 / 30 | |
| 1.2.4 | 20 / 30 | |
| 1.2.3 | 20 / 30 | |
| 1.2.2 | 20 / 30 | |
| 1.2.1 | 20 / 30 | |
| 1.2.0 | 20 / 30 | |
| 1.1.1 | 16 / 38 | |
| 1.1.0 | 16 / 38 | |
| 1.0.102 | 16 / 38 | |
| 1.0.101 | 16 / 38 | |
| 1.0.100 | 16 / 38 | |
| 1.0.99 | 16 / 38 | |
| 1.0.90 | 16 / 38 | |
| 1.0.87 | 16 / 38 | |
| 1.0.83 | 16 / 38 | |
| 1.0.77 | 15 / 38 | |
| 1.0.76 | 15 / 38 | |
| 1.0.75 | 15 / 38 | |
| 1.0.74 | 15 / 38 | |
| 1.0.73 | 15 / 26 | |
| 1.0.72 | 15 / 26 | |
| 1.0.71 | 15 / 26 | |
| 1.0.70 | 15 / 25 | |
| 1.0.69 | 15 / 25 | |
| 1.0.68 | 15 / 25 | |
| 1.0.67 | 15 / 25 | |
| 1.0.66 | 15 / 25 | |
| 1.0.65 | 15 / 25 | |
| 1.0.64 | 15 / 25 | |
| 1.0.63 | 15 / 25 | |
| 1.0.62 | 15 / 25 | |
| 1.0.61 | 15 / 25 | |
| 1.0.60 | 15 / 25 | |
| 1.0.59 | 15 / 25 | |
| 1.0.58 | 15 / 25 | |
| 1.0.57 | 15 / 25 | |
| 1.0.56 | 15 / 25 | |
| 1.0.55 | 15 / 25 | |
| 1.0.54 | 15 / 25 | |
| 1.0.53 | 15 / 25 | |
| 1.0.52 | 15 / 25 | |
| 1.0.51 | 15 / 25 | |
| 1.0.50 | 15 / 25 | |
| 1.0.49 | 15 / 25 | |
| 1.0.48 | 15 / 25 | |
| 1.0.47 | 15 / 25 | |
| 1.0.46 | 15 / 25 | |
| 1.0.45 | 15 / 25 | |
| 1.0.44 | 15 / 25 | |
| 1.0.43 | 15 / 25 | |
| 1.0.42 | 15 / 25 | |
| 1.0.41 | 15 / 22 | |
| 1.0.40 | 15 / 22 | |
| 1.0.39 | 15 / 22 | |
| 1.0.38 | 15 / 22 | |
| 1.0.37 | 15 / 22 | |
| 1.0.36 | 15 / 22 | |
| 1.0.35 | 15 / 22 | |
| 1.0.34 | 15 / 22 | |
| 1.0.33 | 15 / 22 | |
| 1.0.32 | 15 / 22 | |
| 1.0.31 | 15 / 22 | |
| 1.0.30 | 15 / 22 | |
| 1.0.29 | 15 / 22 | |
| 1.0.28 | 15 / 22 | |
| 1.0.27 | 15 / 22 | |
| 1.0.26 | 15 / 22 | |
| 1.0.25 | 17 / 24 | |
| 1.0.24 | 17 / 24 | |
| 1.0.23 | 17 / 24 | |
| 1.0.22 | 17 / 24 | |
| 1.0.21 | 16 / 24 | |
| 1.0.20 | 15 / 23 | |
| 1.0.19 | 15 / 23 | |
| 1.0.18 | 15 / 23 | |
| 1.0.17 | 15 / 23 | |
| 1.0.16 | 15 / 23 | |
| 1.0.15 | 15 / 23 | |
| 1.0.14 | 15 / 23 | |
| 1.0.13 | 15 / 23 | |
| 1.0.12 | 15 / 23 | |
| 1.0.11 | 15 / 23 | |
| 1.0.10 | 15 / 23 | |
| 1.0.9 | 15 / 23 | |
| 1.0.8 | 15 / 23 | |
| 1.0.7 | 15 / 23 | |
| 1.0.6 | 15 / 23 | |
| 1.0.5 | 21 / 23 | |
| 1.0.4 | 12 / 20 | |
| 1.0.3 | 12 / 20 | |
| 1.0.2 | 12 / 20 | |
| 1.0.1 | 12 / 20 |
v1.2.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.90
2 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.87
2 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.83
2 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.77
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.76
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.75
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.74
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.73
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.72
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.71
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.70
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.69
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.68
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.67
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.66
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.65
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.64
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.63
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.62
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.61
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.60
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.59
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.58
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.57
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.56
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.55
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.54
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.53
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.52
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.33
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.30
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.22
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.20
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.19
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.18
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.17
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.16
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.15
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.14
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.13
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.12
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.11
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.10
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.9
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.8
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.7
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.6
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.5
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.