@widergy/energy-ui
Widergy Web Components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): Actively developed UI library; new deps are established, benign packages consistent with feature growth. | ai | |
| dependencies | unvetted-dep:react-flagpack | AI (dependencies): Known flag icon component library; no malware indicators. | ai | |
| dependencies | unvetted-dep:react-signature-canvas | AI (dependencies): Well-known signature input component; no malware indicators. | ai | |
| dependencies | unvetted-dep:intro.js-react | AI (dependencies): React wrapper for intro.js; benign UI dependency. | ai | |
| dependencies | unvetted-dep:intro.js | AI (dependencies): Established open-source onboarding library; no malware indicators. | ai | |
| dependencies | unvetted-dep:@material-ui/lab | AI (dependencies): Official Material-UI lab package; well-known ecosystem dep. | ai | |
| dependencies | unvetted-dep:react-google-maps | AI (dependencies): Established Google Maps React wrapper; no malware indicators. | ai | |
| dependencies | unvetted-dep:@widergy/web-utils | AI (dependencies): Publisher's own scoped utility package; consistent with this org's ecosystem. | ai | |
| dependencies | unvetted-dep:@widergy/energy-hooks | AI (dependencies): Publisher's own scoped hooks package; consistent with this org's ecosystem. | ai | |
| dependencies | unvetted-dep:@trainline/react-skeletor | AI (dependencies): Known Trainline open-source skeleton loader; benign UI dep. | ai | |
| dependencies | unvetted-dep:babel-plugin-inline-react-svg | AI (dependencies): Standard Babel plugin for SVG inlining; no malware indicators. | ai | |
| phantom-deps | phantom-dep:autoprefixer | AI (phantom-deps): PostCSS plugin loaded by config, not direct import. | ai | |
| phantom-deps | phantom-dep:sass-loader | AI (phantom-deps): Webpack loader; loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:react-jss | AI (phantom-deps): JSS styling dep referenced in config; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:@babel/eslint-parser | AI (phantom-deps): Framework-scoped, loaded by eslint config convention. | ai | |
| phantom-deps | phantom-dep:@react-google-maps/api | AI (phantom-deps): Maps dep referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:babel-plugin-inline-react-svg | AI (phantom-deps): Babel plugin loaded by config, not direct import. | ai | |
| phantom-deps | phantom-dep:babel-plugin-named-asset-import | AI (phantom-deps): Babel plugin loaded by config, not direct import. | ai | |
| phantom-deps | phantom-dep:sass | AI (phantom-deps): Build-tool dep used in webpack/babel config; not directly imported in source. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 737 versions; lack of provenance is consistent across all prior releases. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 3.157.1 | 44 / 56 | |
| 3.154.0 | 44 / 56 | |
| 3.151.0 | 44 / 56 | |
| 3.150.0 | 44 / 56 | |
| 3.149.0 | 44 / 56 | |
| 3.148.0 | 44 / 56 | |
| 3.145.1 | 44 / 56 | |
| 3.145.0 | 44 / 56 | |
| 3.141.3 | 44 / 56 | |
| 3.141.2 | 44 / 56 | |
| 3.141.1 | 44 / 56 | |
| 3.137.2 | 44 / 45 | |
| 3.137.1 | 44 / 45 | |
| 3.107.1 | 39 / 41 | |
| 3.104.1 | 39 / 39 | |
| 3.101.0 | 38 / 39 | |
| 3.100.3 | 37 / 39 | |
| 3.86.3 | 35 / 28 | |
| 3.84.0 | 35 / 28 | |
| 3.82.2 | 35 / 28 | |
| 3.78.0 | 35 / 28 | |
| 3.77.0 | 35 / 28 | |
| 3.76.0 | 35 / 28 | |
| 3.75.0 | 35 / 28 | |
| 3.74.0 | 35 / 28 | |
| 3.73.0 | 35 / 28 | |
| 3.72.0 | 35 / 28 | |
| 3.71.1 | 35 / 28 | |
| 3.71.0 | 35 / 28 | |
| 3.70.0 | 35 / 28 | |
| 3.69.7 | 35 / 28 |
v3.157.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.154.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.151.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.150.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.149.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.148.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.145.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.141.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.141.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.141.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.137.2
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sgulino) than the most recent previously approved version (widergy.npm) on 2026-02-10, but sgulino is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.137.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sgulino) than the most recent previously approved version (widergy.npm) on 2026-02-09, but sgulino is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.107.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.104.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.101.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.100.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.86.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.84.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.82.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.78.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.77.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.76.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.75.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.74.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.73.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.72.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.71.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.71.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.70.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.69.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.