← Home

@vertesia/ui

Vertesia UI components and and hooks

42
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

bstefanescuaregnier-vertesialeonruggieromvachette_vertesiahq_commincong-vertesia

Keywords

vertesiaUIreactcomponentshooks

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@radix-ui/react-dropdown-menu AI (phantom-deps): Legitimate UI dep referenced via config/re-export, consistent with other radix-ui phantom deps. ai
source-diff obfuscated-file:lib/vertesia-ui-i18n.js AI (source-diff): Minified i18n translation bundle, not obfuscated logic; no exec/network behavior. ai
maintainer-change maintainer-added AI (maintainer-change): Same trusted org maintainer; not a compromise indicator. ai
provenance publisher-changed AI (provenance): Established org maintainer with strong track record; legitimate transition. ai
dependencies unvetted-dep:fast-xml-validator AI (dependencies): Small XML validation utility added intentionally alongside fast-xml-parser; no known advisories, fits UI library use case. ai
source-diff large-new-source-files AI (source-diff): Size growth matches addition of many legitimate UI component modules and build artifacts. ai
source-diff source-size-tripled AI (source-diff): Size increase explained by new UI components, CodeMirror integration, and bundled source maps. ai
publish-pattern new-deps-added AI (publish-pattern): All 30 new deps are well-known UI/utility packages consistent with a React component library expansion. ai
phantom-deps phantom-dep:react-remove-scroll AI (phantom-deps): Imported indirectly via Radix UI dialog/popover; stable transitive dependency. ai
phantom-deps phantom-dep:katex AI (phantom-deps): Imported indirectly via rehype-katex; stable transitive dependency. ai
phantom-deps phantom-dep:vega-embed AI (phantom-deps): Imported indirectly via react-vega; stable transitive dependency. ai
phantom-deps phantom-dep:aria-hidden AI (phantom-deps): Accessibility utility used indirectly; stable transitive dependency. ai
phantom-deps phantom-dep:@floating-ui/dom AI (phantom-deps): Imported indirectly via @floating-ui/react; stable transitive dependency. ai
phantom-deps phantom-dep:@floating-ui/react AI (phantom-deps): Used indirectly through higher-level Radix UI components. ai
phantom-deps phantom-dep:react-style-singleton AI (phantom-deps): Imported indirectly via react-remove-scroll; stable transitive dependency. ai
phantom-deps phantom-dep:@radix-ui/react-portal AI (phantom-deps): Imported indirectly via higher-level Radix UI components. ai
phantom-deps phantom-dep:react-remove-scroll-bar AI (phantom-deps): Imported indirectly via react-remove-scroll; stable transitive dependency. ai
phantom-deps phantom-dep:@radix-ui/react-focus-scope AI (phantom-deps): Imported indirectly via higher-level Radix UI components. ai
phantom-deps phantom-dep:@radix-ui/react-focus-guards AI (phantom-deps): Imported indirectly via higher-level Radix UI components. ai
phantom-deps phantom-dep:@radix-ui/react-dismissable-layer AI (phantom-deps): Imported indirectly via higher-level Radix UI components. ai
source-diff obfuscated-file:lib/esm/features/store/objects/DocumentPreviewPanel.js AI (source-diff): Sample shows standard TypeScript-compiled ESM output; long lines are from bundled imports, not obfuscation. ai
dependencies unvetted-dep:remark-supersub AI (dependencies): Minor markdown plugin; no known issues, consistent with UI library's markdown rendering feature set. ai
dependencies unvetted-dep:remark-definition-list AI (dependencies): Minor markdown plugin; no known issues, consistent with UI library's markdown rendering feature set. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped @vertesia package; not a typosquat of yup. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @vertesia package; not a typosquat of joi. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped @vertesia package; not a typosquat of pg. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped @vertesia package; not a typosquat of qs. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): Scoped @vertesia package; not a typosquat of uuid. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Loopback IP check in OAuth redirect validation; standard pattern, not exfiltration. ai

Versions (showing 42 of 42)

Version Deps Published
1.4.1 72 / 23
1.4.0 73 / 23
1.3.0 70 / 23
1.2.0 70 / 23
1.1.0 70 / 23
1.0.0 70 / 23
0.82.4 44 / 20
0.82.3 44 / 20
0.82.2 44 / 20
0.82.1 44 / 20
0.82.0 44 / 20
0.81.1 44 / 20
0.81.0 48 / 20
0.80.0 48 / 20
0.79.4 45 / 20
0.79.3 45 / 20
0.79.2 45 / 20
0.79.1 45 / 20
0.78.0 44 / 20
0.77.0 44 / 20
0.76.0 44 / 20
0.74.0 42 / 20
0.73.0 42 / 20
0.72.0 42 / 20
0.71.0 42 / 20
0.70.0 42 / 20
0.69.0 42 / 20
0.68.0 42 / 20
0.67.0 41 / 20
0.66.0 41 / 20
0.65.0 41 / 20
0.64.0 40 / 19
0.63.0 40 / 19
0.62.0 40 / 19
0.61.0 40 / 19
0.60.0 32 / 19
0.59.0 32 / 19
0.58.0 32 / 19
0.57.0 32 / 19
0.56.0 4 / 8
0.55.0 2 / 3
0.54.0 2 / 3

v1.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

2 findings
HIGH New obfuscated file: lib/vertesia-ui-i18n.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.82.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.82.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.81.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: bstefanescu → mincong-vertesia (on 2026-01-28, known maintainer) provenance

This version was published by a different npm account (mincong-vertesia) than the most recent previously approved version (bstefanescu) on 2026-01-28, but mincong-vertesia is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.81.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.80.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.79.4

2 findings
HIGH Publisher changed: bstefanescu → mincong-vertesia (on 2025-12-08) provenance

This version was published by a different npm account than previous versions on 2025-12-08. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.79.3

2 findings
HIGH Publisher changed: bstefanescu → mincong-vertesia (on 2025-11-24) provenance

This version was published by a different npm account than previous versions on 2025-11-24. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.79.2

2 findings
HIGH Publisher changed: bstefanescu → mincong-vertesia (on 2025-11-21) provenance

This version was published by a different npm account than previous versions on 2025-11-21. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.79.1

2 findings
HIGH Publisher changed: bstefanescu → mincong-vertesia (on 2025-11-18) provenance

This version was published by a different npm account than previous versions on 2025-11-18. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.