@washingtonpost/wpds-assets
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/assets/index.9bf4391a.js | AI (source-diff): Vite/React bundler output, not obfuscation; consistent with asset library build. | ai | |
| source-diff | obfuscated-file:dist/assets/index.d1b86017.js | AI (source-diff): Vite/React bundle output, not obfuscation; standard for this asset package's build. | ai | |
| source-diff | obfuscated-file:dist/assets/index.5126c634.js | AI (source-diff): Vite-bundled build output, not true obfuscation; consistent with package's asset-bundling purpose. | ai | |
| source-diff | obfuscated-file:dist/assets/index.456eb59c.js | AI (source-diff): Vite-bundled React/asset code, not obfuscation; consistent with stated package purpose. | ai | |
| source-diff | obfuscated-file:dist/assets/index.3a001672.js | AI (source-diff): Vite/Rollup bundled build output with React internals, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index.f4d71096.js | AI (source-diff): Vite/React bundled build output, not obfuscation; matches package's asset-bundling purpose. | ai | |
| source-diff | obfuscated-file:dist/assets/index.99303d0b.js | AI (source-diff): Vite bundler output (module preload shim, React prod bundle), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index.c93a8cd9.js | AI (source-diff): Vite bundler output (React + preload shim), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index.cc4659e7.js | AI (source-diff): Vite bundle output (React + module preload polyfill), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index.5cb9c159.js | AI (source-diff): Vite-bundled output (React + module preload shim), not true obfuscation. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Legitimate long-standing design-system assets package; README heuristics are noisy false positive. | ai | |
| source-diff | obfuscated-file:dist/assets/index.fabbe02f.js | AI (source-diff): Vite-bundled React/asset code, not obfuscation; consistent with declared build tooling. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Icon library adds many small SVG/asset files by design. | ai | |
| source-diff | obfuscated-file:dist/assets/index.986bf002.js | AI (source-diff): Vite-bundled build output (React + modulepreload polyfill), not obfuscation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Known maintainer artmsilva publishing manually; matches provenance history. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a declared peer/runtime dep; phantom-dep heuristic is a false positive here. | ai | |
| source-diff | obfuscated-file:dist/assets/index.6e1e6ca8.js | AI (source-diff): Standard Vite/React production bundle; minification is expected for this assets package. | ai | |
| source-diff | obfuscated-file:dist/assets/index.181a0bcc.js | AI (source-diff): Vite build artifact (React prod bundle + SVG icons); minification is expected for this design-system assets package. | ai | |
| source-diff | obfuscated-file:dist/assets/index.3961a039.js | AI (source-diff): Standard Vite/React minified bundle for a WP icon library; no malicious patterns in sample. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established 96-version WP design system; gaps between releases are normal for this package. | ai |
Versions (showing 26 of 26)
| Version | Deps | Published |
|---|---|---|
| 2.17.0 | 2 / 15 | |
| 2.16.3 | 2 / 15 | |
| 2.15.2 | 2 / 15 | |
| 2.15.1 | 2 / 15 | |
| 2.15.0 | 2 / 15 | |
| 2.14.0 | 2 / 15 | |
| 2.13.1 | 2 / 15 | |
| 2.13.0 | 2 / 15 | |
| 2.12.0 | 2 / 15 | |
| 2.11.4 | 2 / 15 | |
| 2.11.0 | 2 / 15 | |
| 2.10.2 | 2 / 15 | |
| 2.10.1 | 2 / 15 | |
| 2.10.0 | 2 / 15 | |
| 2.9.0 | 2 / 15 | |
| 2.8.0 | 2 / 15 | |
| 2.7.0 | 2 / 15 | |
| 2.6.2 | 2 / 15 | |
| 2.6.1 | 2 / 15 | |
| 2.6.0 | 2 / 15 | |
| 2.5.0 | 2 / 15 | |
| 2.4.1 | 2 / 15 | |
| 2.4.0 | 2 / 15 | |
| 2.3.0 | 2 / 14 | |
| 2.2.0 | 2 / 14 | |
| 2.1.0 | 2 / 14 |
v2.11.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (artmsilva) than the most recent previously approved version (ebgranger) on 2025-02-07, but artmsilva is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.10.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (artmsilva) than the most recent previously approved version (ebgranger) on 2025-01-30, but artmsilva is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.10.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (artmsilva) than the most recent previously approved version (ebgranger) on 2025-01-30, but artmsilva is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.10.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (artmsilva) than the most recent previously approved version (ebgranger) on 2025-01-23, but artmsilva is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.9.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ebgranger) than the most recent previously approved version (artmsilva) on 2024-07-12, but ebgranger is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.4.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ebgranger) than the most recent previously approved version (artmsilva) on 2024-07-08, but ebgranger is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ebgranger) than the most recent previously approved version (artmsilva) on 2024-05-31, but ebgranger is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.2.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ebgranger) than the most recent previously approved version (artmsilva) on 2024-05-02, but ebgranger is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.