← Home

@vertesia/ui

Vertesia UI components and and hooks

30
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

bstefanescuaregnier-vertesialeonruggieromvachette_vertesiahq_commincong-vertesia

Keywords

vertesiaUIreactcomponentshooks

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): All 30 new deps are well-known UI/utility packages consistent with a React component library expansion. ai
source-diff source-size-tripled AI (source-diff): Size increase explained by new UI components, CodeMirror integration, and bundled source maps. ai
source-diff large-new-source-files AI (source-diff): Size growth matches addition of many legitimate UI component modules and build artifacts. ai
phantom-deps phantom-dep:@floating-ui/dom AI (phantom-deps): Imported indirectly via @floating-ui/react; stable transitive dependency. ai
phantom-deps phantom-dep:aria-hidden AI (phantom-deps): Accessibility utility used indirectly; stable transitive dependency. ai
phantom-deps phantom-dep:@floating-ui/react AI (phantom-deps): Used indirectly through higher-level Radix UI components. ai
phantom-deps phantom-dep:react-remove-scroll AI (phantom-deps): Imported indirectly via Radix UI dialog/popover; stable transitive dependency. ai
phantom-deps phantom-dep:react-style-singleton AI (phantom-deps): Imported indirectly via react-remove-scroll; stable transitive dependency. ai
phantom-deps phantom-dep:@radix-ui/react-portal AI (phantom-deps): Imported indirectly via higher-level Radix UI components. ai
phantom-deps phantom-dep:react-remove-scroll-bar AI (phantom-deps): Imported indirectly via react-remove-scroll; stable transitive dependency. ai
phantom-deps phantom-dep:@radix-ui/react-focus-scope AI (phantom-deps): Imported indirectly via higher-level Radix UI components. ai
phantom-deps phantom-dep:@radix-ui/react-focus-guards AI (phantom-deps): Imported indirectly via higher-level Radix UI components. ai
phantom-deps phantom-dep:@radix-ui/react-dismissable-layer AI (phantom-deps): Imported indirectly via higher-level Radix UI components. ai
phantom-deps phantom-dep:katex AI (phantom-deps): Imported indirectly via rehype-katex; stable transitive dependency. ai
phantom-deps phantom-dep:vega-embed AI (phantom-deps): Imported indirectly via react-vega; stable transitive dependency. ai
source-diff obfuscated-file:lib/esm/features/store/objects/DocumentPreviewPanel.js AI (source-diff): Sample shows standard TypeScript-compiled ESM output; long lines are from bundled imports, not obfuscation. ai
dependencies unvetted-dep:remark-definition-list AI (dependencies): Minor markdown plugin; no known issues, consistent with UI library's markdown rendering feature set. ai
dependencies unvetted-dep:remark-supersub AI (dependencies): Minor markdown plugin; no known issues, consistent with UI library's markdown rendering feature set. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped @vertesia package; not a typosquat of pg. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @vertesia package; not a typosquat of joi. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped @vertesia package; not a typosquat of yup. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): Scoped @vertesia package; not a typosquat of uuid. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Loopback IP check in OAuth redirect validation; standard pattern, not exfiltration. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped @vertesia package; not a typosquat of qs. ai

Versions (showing 30 of 30)

Version Deps Published
1.3.0 70 / 23
1.2.0 70 / 23
1.1.0 70 / 23
0.82.4 44 / 20
0.82.1 44 / 20
0.82.0 44 / 20
0.78.0 44 / 20
0.77.0 44 / 20
0.76.0 44 / 20
0.74.0 42 / 20
0.73.0 42 / 20
0.72.0 42 / 20
0.71.0 42 / 20
0.70.0 42 / 20
0.69.0 42 / 20
0.68.0 42 / 20
0.67.0 41 / 20
0.66.0 41 / 20
0.65.0 41 / 20
0.64.0 40 / 19
0.63.0 40 / 19
0.62.0 40 / 19
0.61.0 40 / 19
0.60.0 32 / 19
0.59.0 32 / 19
0.58.0 32 / 19
0.57.0 32 / 19
0.56.0 4 / 8
0.55.0 2 / 3
0.54.0 2 / 3

v1.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.82.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.82.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.78.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.77.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.76.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.74.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.73.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.72.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.71.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.70.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.69.0

3 findings
HIGH Publisher changed: bstefanescu → aregnier-vertesia (on 2025-07-17) provenance

This version was published by a different npm account than previous versions on 2025-07-17. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.68.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.67.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.66.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.65.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.64.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.63.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.62.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.61.0

2 findings
HIGH New obfuscated file: lib/esm/features/store/objects/DocumentPreviewPanel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.60.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.59.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.58.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.57.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.56.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.55.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.54.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.