@things-factory/auth-ui
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@things-factory/more-base | AI (dependencies): First-party sibling package in the same monorepo. | ai | |
| dependencies | unvetted-dep:@operato/lottie-player | AI (dependencies): Known companion lib used throughout things-factory ecosystem. | ai | |
| dependencies | unvetted-dep:@operato/i18n | AI (dependencies): Known companion lib used throughout things-factory ecosystem. | ai | |
| dependencies | unvetted-dep:@material/mwc-button | AI (dependencies): Standard Material Web Components lib, widely used. | ai | |
| dependencies | unvetted-dep:@material/mwc-textarea | AI (dependencies): Standard Material Web Components lib, widely used. | ai | |
| dependencies | unvetted-dep:@material/mwc-textfield | AI (dependencies): Standard Material Web Components lib, widely used. | ai | |
| dependencies | unvetted-dep:@material/mwc-icon-button | AI (dependencies): Standard Material Web Components lib, widely used. | ai | |
| dependencies | unvetted-dep:@things-factory/auth-base | AI (dependencies): First-party sibling package in the same monorepo. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Diff vs last approved shows no material changes; likely benign monorepo restructuring. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainer is a known, long-track-record account per provenance context. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Routine monorepo maintainer roster churn, no material code change. | ai | |
| semgrep | semgrep:toplevel-fetch | AI (semgrep): Fetch calls are inside async methods for auth credential retrieval — core functionality, not exfiltration. | ai | |
| phantom-deps | phantom-dep:@operato/moment-timezone-es | AI (phantom-deps): Declared dep; phantom-dep heuristic false positive for this package's build structure. | ai | |
| phantom-deps | phantom-dep:base64url | AI (phantom-deps): Declared dep used in bundled/server code; phantom-dep heuristic fires on import style differences. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 9.2.33 | 13 / 0 | |
| 9.2.30 | 13 / 0 | |
| 9.2.29 | 13 / 0 | |
| 9.2.24 | 13 / 0 | |
| 9.2.19 | 13 / 0 | |
| 9.2.17 | 13 / 0 | |
| 9.2.16 | 13 / 0 | |
| 9.2.13 | 13 / 0 | |
| 9.2.5 | 13 / 0 | |
| 9.1.19 | 13 / 0 | |
| 8.0.88 | 13 / 0 | |
| 8.0.87 | 13 / 0 | |
| 8.0.86 | 13 / 0 | |
| 8.0.75 | 13 / 0 | |
| 8.0.74 | 13 / 0 | |
| 8.0.64 | 13 / 0 | |
| 8.0.63 | 13 / 0 | |
| 6.4.10 | 16 / 0 | |
| 6.4.8 | 16 / 0 | |
| 4.3.764 | 14 / 0 | |
| 4.3.740 | 14 / 0 | |
| 4.3.725 | 14 / 0 | |
| 4.3.705 | 14 / 0 | |
| 4.3.689 | 14 / 0 |
v9.2.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.16
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (heartyoh) on 2026-03-25, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v9.2.13
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (heartyoh) than the most recent previously approved version (nalshya113) on 2026-03-19, but heartyoh is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v9.2.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (heartyoh) on 2026-03-06, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v9.1.19
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (heartyoh) than the most recent previously approved version (nalshya113) on 2025-11-25, but heartyoh is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.86
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (heartyoh) on 2026-03-05, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.75
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (heartyoh) on 2026-01-12, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.74
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (heartyoh) on 2026-01-02, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.0.64
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.63
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nalshya113) than the most recent previously approved version (horwengliang95) on 2025-11-03, but nalshya113 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (heartyoh) than the most recent previously approved version (nalshya113) on 2026-03-29, but heartyoh is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.689
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.