@uniweb/runtime
Minimal runtime for loading Uniweb foundations
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/app/assets/index-DSQoGb1v.js | AI (source-diff): Rollup-bundled app code, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-DFtjIARq.js | AI (source-diff): Bundled yaml library code, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-Bq66t-e8.js | AI (source-diff): Bundled Vite/Rollup output, not obfuscation; no malicious behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-X3XXanGI.js | AI (source-diff): Minified React build output, standard bundling. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-ws6oKIIt.js | AI (source-diff): Minified React build output, standard bundling. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-D4JWwegf.js | AI (source-diff): Bundled yaml library code, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-S3vw9Fm0.js | AI (source-diff): Bundled Vite/esbuild output, standard minified app bundle. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-BGRRYv_5.js | AI (source-diff): Vite/rollup bundled output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-4-Tj6sUj.js | AI (source-diff): Rollup-bundled app code, unminified-symbol vendor chunk, no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-C6EFXW_H.js | AI (source-diff): Bundled yaml lib chunk, standard minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-CxUeIbEw.js | AI (source-diff): Bundled React runtime chunk, standard minification. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-VvOM7xKK.js | AI (source-diff): Bundled react-dom chunk, standard minification. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size growth matches new bundled dist assets, not injected payload. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-sDacLXBC.js | AI (source-diff): Vite/Rollup bundled output with sourcemaps, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-4Jlbab_T.js | AI (source-diff): Vite/Rollup bundled output with sourcemaps, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/worker-runtime.js | AI (source-diff): esbuild bundler banner + bundled React source, standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-DesPD4M1.js | AI (source-diff): Bundled yaml lib code, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-Ca9aM7z2.js | AI (source-diff): Bundled rollup output, not obfuscation; recognizable library code in sample. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-CsqlosR8.js | AI (source-diff): Bundled Vite output with source maps, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-Bxvdtdsc.js | AI (source-diff): Bundled Vite output with source maps, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-C6TPxGbh.js | AI (source-diff): Minified yaml library bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-C0udIITE.js | AI (source-diff): Minified React scheduler bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-kA4PVysc.js | AI (source-diff): Minified React core bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app/assets/index-CsyMBO9p.js | AI (source-diff): Rollup-bundled theming CSS generator, matches package purpose. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party @uniweb org packages, not external/unvetted. | ai | |
| provenance | missing-githead | AI (provenance): Metadata-only gap; no behavioral change, publisher has clean track record. | ai | |
| dependencies | unvetted-dep:@uniweb/theming | AI (dependencies): @uniweb/theming is a first-party dep from the same proximify publisher with a clean track record; stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Provenance absence is common; no other risk signals present for this package. | ai |
Versions (showing 37 of 137)
| Version | Deps | Published |
|---|---|---|
| 0.5.8 | 1 / 2 | |
| 0.5.7 | 1 / 2 | |
| 0.5.6 | 1 / 2 | |
| 0.5.5 | 1 / 2 | |
| 0.5.4 | 1 / 2 | |
| 0.5.3 | 1 / 2 | |
| 0.5.2 | 1 / 2 | |
| 0.5.1 | 1 / 2 | |
| 0.5.0 | 1 / 2 | |
| 0.4.4 | 1 / 2 | |
| 0.4.3 | 1 / 2 | |
| 0.4.2 | 1 / 2 | |
| 0.4.1 | 1 / 2 | |
| 0.4.0 | 1 / 2 | |
| 0.3.1 | 1 / 2 | |
| 0.3.0 | 1 / 2 | |
| 0.2.20 | 1 / 2 | |
| 0.2.19 | 1 / 2 | |
| 0.2.18 | 1 / 2 | |
| 0.2.17 | 1 / 2 | |
| 0.2.16 | 1 / 2 | |
| 0.2.15 | 1 / 2 | |
| 0.2.13 | 1 / 0 | |
| 0.2.12 | 1 / 0 | |
| 0.2.11 | 1 / 0 | |
| 0.2.10 | 1 / 0 | |
| 0.2.8 | 1 / 0 | |
| 0.2.7 | 1 / 0 | |
| 0.2.6 | 1 / 0 | |
| 0.2.5 | 1 / 0 | |
| 0.2.4 | 1 / 0 | |
| 0.2.3 | 1 / 0 | |
| 0.2.2 | 1 / 0 | |
| 0.2.1 | 1 / 0 | |
| 0.1.2 | 2 / 0 | |
| 0.1.1 | 2 / 0 | |
| 0.1.0 | 1 / 0 |
v0.5.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.18
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: proximify.
v0.2.17
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: proximify.
v0.2.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.15
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: proximify.
v0.2.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.6
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: proximify.
v0.2.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.4
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: proximify.
v0.2.3
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: proximify.
v0.2.2
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: proximify.
v0.2.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: proximify.