@tencentcloud/ai-desk-customer-vue
Vue2/Vue3 UIKit for AI Desk
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:@aidesk/uikit-engine/index.js | AI (source-diff): Minified bundled build output (webpack-style), not true obfuscation; no malicious behavior found. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size jump from inlining the previously external tui-* engine deps; expected. | ai | |
| source-diff | obfuscated-file:./@aidesk/uikit-engine/index.js | AI (source-diff): Minified bundle output of Tencent UIKit engine, not obfuscation; benign build artifact. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Legitimate Tencent org publisher with prior approved versions; inactivity gap consistent with product release cadence, not takeover. | ai | |
| dependencies | unvetted-dep:@tencentcloud/tui-emoji-plugin | AI (dependencies): First-party Tencent Cloud dependency; same org scope as this package. | ai | |
| dependencies | unvetted-dep:@tencentcloud/tui-core | AI (dependencies): First-party Tencent Cloud dependency; same org scope as this package. | ai | |
| dependencies | unvetted-dep:@tencentcloud/universal-api | AI (dependencies): First-party Tencent Cloud dependency; same org scope as this package. | ai | |
| dependencies | unvetted-dep:@tencentcloud/chat-uikit-engine | AI (dependencies): First-party Tencent Cloud dependency; same org scope as this package. | ai | |
| dependencies | unvetted-dep:mp-html | AI (dependencies): Well-known WeChat mini-program HTML renderer; stable open-source library. | ai | |
| dependencies | unvetted-dep:js-audio-recorder | AI (dependencies): Known audio recording utility; expected dependency for a customer service chat UIKit. | ai | |
| dependencies | unvetted-dep:countries-and-timezones | AI (dependencies): Well-known utility library with no security concerns. | ai | |
| phantom-deps | phantom-dep:dayjs | AI (phantom-deps): Declared in package.json; phantom-dep heuristic false positive for this bundled UIKit. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Declared in package.json; phantom-dep heuristic false positive for this bundled UIKit. | ai | |
| phantom-deps | phantom-dep:mp-html | AI (phantom-deps): Declared in package.json; phantom-dep heuristic false positive for this bundled UIKit. | ai | |
| phantom-deps | phantom-dep:@types/lodash | AI (phantom-deps): Type-only package; framework-scoped, expected false positive. | ai | |
| phantom-deps | phantom-dep:vue-clipboard3 | AI (phantom-deps): Declared in package.json; phantom-dep heuristic false positive for this bundled UIKit. | ai | |
| phantom-deps | phantom-dep:@tencentcloud/tui-emoji-plugin | AI (phantom-deps): First-party same-org dependency; phantom-dep false positive. | ai | |
| provenance | no-provenance | AI (provenance): Tencent Cloud org package; lack of Sigstore provenance is common and not a disqualifier here. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-paragraph | AI (phantom-deps): Bundled tiptap dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-placeholder | AI (phantom-deps): Bundled tiptap dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:js-audio-recorder | AI (phantom-deps): Declared dep referenced in config; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:tim-upload-plugin | AI (phantom-deps): Declared Tencent dep referenced in config; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:countries-and-timezones | AI (phantom-deps): Declared dep referenced in config; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-mention | AI (phantom-deps): Bundled tiptap dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-text | AI (phantom-deps): Bundled tiptap dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tiptap/pm | AI (phantom-deps): Bundled tiptap dep; phantom-dep heuristic fires on bundled/config-referenced packages. | ai | |
| phantom-deps | phantom-dep:@tiptap/suggestion | AI (phantom-deps): Bundled tiptap dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-document | AI (phantom-deps): Bundled tiptap dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tiptap/core | AI (phantom-deps): Bundled tiptap dep; stable false positive for this package. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 1.7.6 | 15 / 0 | |
| 1.7.5 | 15 / 0 | |
| 1.7.4 | 15 / 0 | |
| 1.7.3 | 15 / 0 | |
| 1.7.2 | 15 / 0 | |
| 1.7.1 | 15 / 0 | |
| 1.7.0 | 15 / 0 | |
| 1.6.10 | 17 / 0 | |
| 1.6.9 | 17 / 0 | |
| 1.6.8 | 16 / 0 | |
| 1.6.7 | 19 / 0 | |
| 1.6.6 | 21 / 0 | |
| 1.6.4 | 21 / 0 | |
| 1.6.3 | 21 / 0 | |
| 1.6.2 | 21 / 0 | |
| 1.6.0 | 21 / 0 | |
| 1.5.11 | 20 / 0 | |
| 1.5.10 | 20 / 0 | |
| 1.5.9 | 20 / 0 | |
| 1.5.8 | 20 / 0 | |
| 1.5.6 | 20 / 0 | |
| 1.5.5 | 20 / 0 | |
| 1.5.4 | 20 / 0 | |
| 1.5.3 | 19 / 0 | |
| 1.5.2 | 19 / 0 | |
| 1.5.1 | 19 / 0 | |
| 1.5.0 | 19 / 0 | |
| 1.4.0 | 19 / 0 | |
| 1.3.0 | 19 / 0 | |
| 1.1.0 | 19 / 0 | |
| 1.0.1 | 19 / 0 | |
| 1.0.0 | 19 / 0 |
v1.7.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.