@trilogy-ds/react
Trilogy react framework design system for Bouygues Telecom
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-removed | AI (maintainer-change): Same publisher transition to GitHub Actions provenance; benign org restructuring. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Coincides with move to CI/CD trusted publisher with provenance, not a compromise indicator. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): react-native-svg and sibling @trilogy-ds/locales are legitimate UI/i18n deps for this design system. | ai | |
| source-diff | obfuscated-file:lib/components/datepicker/DatePicker.js | AI (source-diff): Compiled TS output with long lines, not true obfuscation; no malicious behavior present. | ai | |
| source-diff | obfuscated-file:lib/components/prompt/files/file/PromptFile.native.js | AI (source-diff): Compiled TS output (tslib), not true obfuscation; sample is readable component code. | ai | |
| source-diff | obfuscated-file:lib/components/tabs/tab-list/tab/Tab.native.js | AI (source-diff): Compiled TS output with tslib helpers, not true obfuscation. | ai | |
| source-diff | obfuscated-file:lib/components/checkbox/tiles/tile/CheckboxTile.native.js | AI (source-diff): Compiled TS output with tslib helpers, not true obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New native-platform component files, consistent with library scope. | ai | |
| dependencies | unvetted-dep:@trilogy-ds/locales | AI (dependencies): First-party Bouygues Telecom locales package within the same trilogy-ds namespace. | ai | |
| dependencies | unvetted-dep:react-native-modal | AI (dependencies): Standard React Native UI dependency for a corporate design system; expected and stable across versions. | ai | |
| dependencies | unvetted-dep:@react-native-picker/picker | AI (dependencies): Official React Native community picker component; expected dependency for this package. | ai | |
| dependencies | unvetted-dep:@ptomasroos/react-native-multi-slider | AI (dependencies): Known React Native slider component; stable dependency for this design system. | ai | |
| phantom-deps | phantom-dep:react-native-gesture-handler | AI (phantom-deps): Platform-specific peer/native dep for React Native; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:@react-native-picker/picker | AI (phantom-deps): Platform-specific binary package; phantom-dep heuristic is a known false positive for RN native modules. | ai | |
| phantom-deps | phantom-dep:shortid | AI (phantom-deps): Utility dep referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:color | AI (phantom-deps): Design system package; color is a utility dep used in config/style logic, not a direct import concern. | ai | |
| license | uncommon-license:UNLICENSED | AI (license): Proprietary Bouygues Telecom internal package; UNLICENSED is intentional across all versions. | ai | |
| phantom-deps | phantom-dep:rollup-plugin-copy | AI (phantom-deps): Build-time tool referenced in config files only; not a runtime concern. | ai |
Versions (showing 47 of 47)
| Version | Deps | Published |
|---|---|---|
| 4.18.1 | 10 / 6 | |
| 4.17.0 | 10 / 1 | |
| 4.16.3 | 14 / 1 | |
| 4.16.2 | 14 / 1 | |
| 4.16.1 | 14 / 1 | |
| 4.15.3 | 13 / 1 | |
| 4.15.2 | 13 / 1 | |
| 4.15.1 | 13 / 1 | |
| 4.15.0 | 13 / 1 | |
| 4.14.4 | 13 / 1 | |
| 4.14.3 | 13 / 1 | |
| 4.14.2 | 13 / 1 | |
| 4.14.0 | 13 / 1 | |
| 4.13.0 | 14 / 1 | |
| 4.12.1 | 14 / 1 | |
| 4.12.0 | 14 / 1 | |
| 4.11.0 | 14 / 0 | |
| 4.10.2 | 14 / 0 | |
| 4.10.1 | 14 / 0 | |
| 4.10.0 | 14 / 0 | |
| 4.9.3 | 14 / 0 | |
| 4.9.2 | 14 / 0 | |
| 4.9.1 | 14 / 0 | |
| 4.8.2 | 14 / 0 | |
| 4.8.1 | 14 / 0 | |
| 4.7.5 | 14 / 0 | |
| 4.7.4 | 14 / 0 | |
| 4.7.1 | 14 / 0 | |
| 4.7.0 | 14 / 0 | |
| 4.6.1 | 14 / 0 | |
| 4.6.0 | 14 / 0 | |
| 4.5.1 | 14 / 0 | |
| 4.5.0 | 14 / 0 | |
| 4.4.2 | 14 / 0 | |
| 4.4.1 | 14 / 0 | |
| 4.4.0 | 14 / 0 | |
| 4.3.0 | 14 / 0 | |
| 4.2.1 | 13 / 0 | |
| 4.1.2 | 13 / 0 | |
| 4.1.1 | 13 / 0 | |
| 4.1.0 | 13 / 0 | |
| 4.0.6 | 12 / 0 | |
| 4.0.5 | 12 / 0 | |
| 4.0.4 | 12 / 0 | |
| 4.0.2 | 12 / 0 | |
| 4.0.1 | 12 / 0 | |
| 4.0.0 | 12 / 0 |
v4.18.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (julienmo) on 2026-07-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v4.4.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.