@tenphi/tasty
A design-system-integrated styling system and DSL for concise, state-aware UI styling
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index-mWACW3QW.d.ts | AI (source-diff): Bundled TypeScript declaration file with long re-export lines; standard tsdown/rollup output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-DMGEDjlc.d.ts | AI (source-diff): Bundled .d.ts from tsdown; long lines are normal for rollup'd type declarations, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-IOt-QoB7.d.ts | AI (source-diff): Bundled .d.ts declaration file with long import lines; not obfuscated code, stable pattern for this build tool. | ai | |
| source-diff | obfuscated-file:dist/index-sk1sxVI3.d.ts | AI (source-diff): Bundled .d.ts declaration file with long import lines; normal tsdown output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-J7y6BV89.d.ts | AI (source-diff): Bundled TypeScript declaration file from tsdown; long lines are normal for rollup'd .d.ts outputs, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/core/index.d.ts | AI (source-diff): Long lines are TypeScript declaration imports, not obfuscated code; stable false positive for this package. | ai | |
| provenance | missing-githead | AI (provenance): Package has SLSA provenance attestation; missing gitHead is a cosmetic metadata gap, not a security risk. | ai | |
| source-diff | obfuscated-file:dist/index-ZRxZWzlj.d.ts | AI (source-diff): Bundled .d.ts declaration file with long import lines; not executable, normal tsdown output for this package. | ai | |
| source-diff | obfuscated-file:dist/index-FuQphaEO.d.ts | AI (source-diff): Long-line .d.ts files are normal bundled TypeScript declarations from tsdown; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-o7zV2yCr.d.ts | AI (source-diff): Bundled .d.ts type declaration file with long import lines; not obfuscated code, stable pattern for this build toolchain. | ai |
Versions (showing 72 of 72)
| Version | Deps | Published |
|---|---|---|
| 2.9.1 | 1 / 28 | |
| 2.9.0 | 1 / 28 | |
| 2.8.2 | 1 / 28 | |
| 2.8.1 | 1 / 28 | |
| 2.8.0 | 1 / 28 | |
| 2.7.0 | 1 / 28 | |
| 2.6.5 | 1 / 28 | |
| 2.6.4 | 1 / 24 | |
| 2.6.3 | 1 / 24 | |
| 2.6.2 | 1 / 24 | |
| 2.6.1 | 1 / 24 | |
| 2.6.0 | 1 / 24 | |
| 2.5.0 | 1 / 24 | |
| 2.4.0 | 1 / 24 | |
| 2.3.1 | 1 / 24 | |
| 2.3.0 | 1 / 24 | |
| 2.2.0 | 1 / 24 | |
| 2.1.2 | 1 / 24 | |
| 2.1.1 | 1 / 24 | |
| 2.1.0 | 1 / 24 | |
| 2.0.4 | 1 / 23 | |
| 2.0.3 | 1 / 23 | |
| 2.0.2 | 1 / 23 | |
| 2.0.1 | 1 / 23 | |
| 2.0.0 | 1 / 23 | |
| 1.5.4 | 1 / 23 | |
| 1.5.3 | 1 / 23 | |
| 1.5.2 | 1 / 23 | |
| 1.5.1 | 1 / 23 | |
| 1.5.0 | 1 / 23 | |
| 1.4.2 | 1 / 23 | |
| 1.4.1 | 1 / 23 | |
| 1.4.0 | 1 / 23 | |
| 1.3.0 | 1 / 23 | |
| 1.2.0 | 1 / 23 | |
| 1.1.0 | 1 / 23 | |
| 1.0.0 | 1 / 23 | |
| 0.17.1 | 1 / 23 | |
| 0.17.0 | 1 / 23 | |
| 0.16.1 | 1 / 23 | |
| 0.16.0 | 1 / 23 | |
| 0.15.3 | 1 / 23 | |
| 0.15.2 | 1 / 23 | |
| 0.15.1 | 1 / 23 | |
| 0.15.0 | 1 / 23 | |
| 0.14.2 | 1 / 23 | |
| 0.14.1 | 1 / 23 | |
| 0.14.0 | 1 / 23 | |
| 0.13.1 | 1 / 23 | |
| 0.13.0 | 1 / 23 | |
| 0.12.0 | 1 / 23 | |
| 0.11.0 | 1 / 23 | |
| 0.10.1 | 2 / 23 | |
| 0.10.0 | 2 / 23 | |
| 0.9.0 | 1 / 23 | |
| 0.8.0 | 1 / 23 | |
| 0.7.1 | 1 / 23 | |
| 0.7.0 | 1 / 23 | |
| 0.6.0 | 1 / 23 | |
| 0.5.4 | 1 / 23 | |
| 0.5.3 | 1 / 20 | |
| 0.5.2 | 1 / 20 | |
| 0.5.1 | 1 / 20 | |
| 0.5.0 | 1 / 20 | |
| 0.4.2 | 1 / 20 | |
| 0.4.1 | 4 / 20 | |
| 0.4.0 | 4 / 20 | |
| 0.3.0 | 4 / 20 | |
| 0.2.0 | 4 / 20 | |
| 0.1.3 | 4 / 20 | |
| 0.1.2 | 4 / 20 | |
| 0.1.0 | 4 / 20 |
v2.9.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.8.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.