← Home

@trilogy-ds/react

Trilogy react framework design system for Bouygues Telecom

47
Versions
UNLICENSED
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

bytelravi.khatwanijulienmoexavierbartymaury

Keywords

reactdesign system

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Same publisher transition to GitHub Actions provenance; benign org restructuring. ai
maintainer-change maintainer-added AI (maintainer-change): Coincides with move to CI/CD trusted publisher with provenance, not a compromise indicator. ai
publish-pattern new-deps-added AI (publish-pattern): react-native-svg and sibling @trilogy-ds/locales are legitimate UI/i18n deps for this design system. ai
source-diff obfuscated-file:lib/components/datepicker/DatePicker.js AI (source-diff): Compiled TS output with long lines, not true obfuscation; no malicious behavior present. ai
source-diff obfuscated-file:lib/components/prompt/files/file/PromptFile.native.js AI (source-diff): Compiled TS output (tslib), not true obfuscation; sample is readable component code. ai
source-diff obfuscated-file:lib/components/tabs/tab-list/tab/Tab.native.js AI (source-diff): Compiled TS output with tslib helpers, not true obfuscation. ai
source-diff obfuscated-file:lib/components/checkbox/tiles/tile/CheckboxTile.native.js AI (source-diff): Compiled TS output with tslib helpers, not true obfuscation. ai
source-diff large-new-source-files AI (source-diff): New native-platform component files, consistent with library scope. ai
dependencies unvetted-dep:@trilogy-ds/locales AI (dependencies): First-party Bouygues Telecom locales package within the same trilogy-ds namespace. ai
dependencies unvetted-dep:react-native-modal AI (dependencies): Standard React Native UI dependency for a corporate design system; expected and stable across versions. ai
dependencies unvetted-dep:@react-native-picker/picker AI (dependencies): Official React Native community picker component; expected dependency for this package. ai
dependencies unvetted-dep:@ptomasroos/react-native-multi-slider AI (dependencies): Known React Native slider component; stable dependency for this design system. ai
phantom-deps phantom-dep:react-native-gesture-handler AI (phantom-deps): Platform-specific peer/native dep for React Native; not directly imported by design. ai
phantom-deps phantom-dep:@react-native-picker/picker AI (phantom-deps): Platform-specific binary package; phantom-dep heuristic is a known false positive for RN native modules. ai
phantom-deps phantom-dep:shortid AI (phantom-deps): Utility dep referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:color AI (phantom-deps): Design system package; color is a utility dep used in config/style logic, not a direct import concern. ai
license uncommon-license:UNLICENSED AI (license): Proprietary Bouygues Telecom internal package; UNLICENSED is intentional across all versions. ai
phantom-deps phantom-dep:rollup-plugin-copy AI (phantom-deps): Build-time tool referenced in config files only; not a runtime concern. ai

Versions (showing 47 of 47)

Version Deps Published
4.18.1 10 / 6
4.17.0 10 / 1
4.16.3 14 / 1
4.16.2 14 / 1
4.16.1 14 / 1
4.15.3 13 / 1
4.15.2 13 / 1
4.15.1 13 / 1
4.15.0 13 / 1
4.14.4 13 / 1
4.14.3 13 / 1
4.14.2 13 / 1
4.14.0 13 / 1
4.13.0 14 / 1
4.12.1 14 / 1
4.12.0 14 / 1
4.11.0 14 / 0
4.10.2 14 / 0
4.10.1 14 / 0
4.10.0 14 / 0
4.9.3 14 / 0
4.9.2 14 / 0
4.9.1 14 / 0
4.8.2 14 / 0
4.8.1 14 / 0
4.7.5 14 / 0
4.7.4 14 / 0
4.7.1 14 / 0
4.7.0 14 / 0
4.6.1 14 / 0
4.6.0 14 / 0
4.5.1 14 / 0
4.5.0 14 / 0
4.4.2 14 / 0
4.4.1 14 / 0
4.4.0 14 / 0
4.3.0 14 / 0
4.2.1 13 / 0
4.1.2 13 / 0
4.1.1 13 / 0
4.1.0 13 / 0
4.0.6 12 / 0
4.0.5 12 / 0
4.0.4 12 / 0
4.0.2 12 / 0
4.0.1 12 / 0
4.0.0 12 / 0

v4.18.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: julienmo → GitHub Actions (on 2026-07-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (julienmo) on 2026-07-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v4.4.0

3 findings
HIGH New obfuscated file: lib/components/checkbox/tiles/tile/CheckboxTile.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/tabs/tab-list/tab/Tab.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.0

3 findings
HIGH New obfuscated file: lib/components/checkbox/tiles/tile/CheckboxTile.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/tabs/tab-list/tab/Tab.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.1

3 findings
HIGH New obfuscated file: lib/components/checkbox/tiles/tile/CheckboxTile.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/tabs/tab-list/tab/Tab.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.2

3 findings
HIGH New obfuscated file: lib/components/checkbox/tiles/tile/CheckboxTile.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/tabs/tab-list/tab/Tab.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.1

3 findings
HIGH New obfuscated file: lib/components/checkbox/tiles/tile/CheckboxTile.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/tabs/tab-list/tab/Tab.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.0

3 findings
HIGH New obfuscated file: lib/components/checkbox/tiles/tile/CheckboxTile.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/tabs/tab-list/tab/Tab.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.6

3 findings
HIGH New obfuscated file: lib/components/checkbox/tiles/tile/CheckboxTile.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/tabs/tab-list/tab/Tab.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.5

3 findings
HIGH New obfuscated file: lib/components/checkbox/tiles/tile/CheckboxTile.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/tabs/tab-list/tab/Tab.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.4

3 findings
HIGH New obfuscated file: lib/components/checkbox/tiles/tile/CheckboxTile.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/tabs/tab-list/tab/Tab.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.2

3 findings
HIGH New obfuscated file: lib/components/checkbox/tiles/tile/CheckboxTile.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/components/tabs/tab-list/tab/Tab.native.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.