← Home

@wisemen/vue-core-design-system

A Vue 3 design system package for Wisemen projects.

33
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

wouter.appwisekobe-kwanten-wisemenjorenvandeweyerrobbe95fullmetaljsmaartensijmkenswisemen-sysopspeethadaanpersoonsjonasvannieuwenhuijsenyuhanghujonasbeckerssebastiaanvanspauwenjeroen-vc

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/locales-DDxq9_IH.cjs AI (source-diff): File is a minified locale string bundle (i18n key-value pairs), not obfuscated malicious code. Stable pattern for this package. ai
source-diff obfuscated-file:dist/locales-C9xR5jDn.cjs AI (source-diff): Minified locale strings file; plaintext i18n content, not obfuscated. ai
source-diff obfuscated-file:dist/locales-D6myqwkO.cjs AI (source-diff): File is a minified locale/i18n string bundle — no obfuscation, no executable logic. ai
source-diff obfuscated-file:dist/locales-DgSXUfDb.cjs AI (source-diff): File is a minified locale/i18n string bundle — plaintext key-value pairs, no obfuscation or malicious code. ai
source-diff obfuscated-file:dist/locales-C45uyfCG.cjs AI (source-diff): File is a minified locale string bundle with no executable code; not obfuscated in any meaningful sense. ai
source-diff obfuscated-file:dist/locales-BWBAGbXi.cjs AI (source-diff): Minified locale string bundle; no executable logic, purely i18n key-value data. ai
phantom-deps phantom-dep:vue-sonner AI (phantom-deps): vue-sonner is also a peerDependency; phantom-dep false positive for this package. ai
phantom-deps phantom-dep:@wisemen/vue-core-api-utils AI (phantom-deps): Same-org package; phantom-dep heuristic false positive. ai
source-diff obfuscated-file:dist/locales-C4VLVD0U.cjs AI (source-diff): File is a minified i18n locale bundle with plain-text string keys — not obfuscated malicious code. ai
source-diff large-new-source-files AI (source-diff): Growing design system; new files correspond to legitimate component additions. ai
source-diff obfuscated-file:dist/index.cjs AI (source-diff): Standard minified bundle output for a Vue component library; sample shows legitimate Vue/vueuse code patterns. ai
source-diff source-size-tripled AI (source-diff): Size growth consistent with new component additions in an actively developed design system. ai
phantom-deps phantom-dep:country-flag-icons AI (phantom-deps): country-flag-icons is a CSS/data asset dep; not directly imported in JS but legitimately used. ai
source-diff obfuscated-file:dist/locales-WMT_ybiO.cjs AI (source-diff): File is a minified i18n locale map of plain UI strings; no executable code or obfuscation. ai
source-diff obfuscated-file:dist/locales-C7_BArir.cjs AI (source-diff): File is a minified i18n locale dictionary — long lines are string key-value pairs, not obfuscated code. ai
source-diff obfuscated-file:dist/locales-DpZYr8Pk.cjs AI (source-diff): File is a minified i18n locale bundle with plain English UI strings; not obfuscated executable code. ai
source-diff obfuscated-file:dist/locales-DHNt4L1K.cjs AI (source-diff): File is a minified i18n locale dictionary with plain readable string keys — not obfuscated code. ai
dependencies unvetted-dep:@wisemen/vue-core-icons AI (dependencies): Same org scope (@wisemen); consistent dependency across versions with no malicious indicators. ai
phantom-deps phantom-dep:tailwindcss AI (phantom-deps): Tailwindcss is a build/styling tool referenced in config files; not a runtime import — stable FP for this package. ai
phantom-deps phantom-dep:@wisemen/vue-core-icons AI (phantom-deps): Same-org dependency; likely re-exported or used indirectly — stable FP for this package. ai
phantom-deps phantom-dep:vue-component-meta AI (phantom-deps): Used in build/tooling config, not directly imported at runtime — stable FP for this package. ai
phantom-deps phantom-dep:@tailwindcss/vite AI (phantom-deps): Vite plugin referenced in build config only; not a runtime import — stable FP for this package. ai

Versions (showing 33 of 33)

Version Deps Published
1.4.1 15 / 36
1.4.0 15 / 36
1.3.2 14 / 36
1.3.1 14 / 36
1.3.0 14 / 36
1.2.0 14 / 36
1.1.1 14 / 36
1.1.0 14 / 36
1.0.0 13 / 36
0.17.0 11 / 35
0.16.0 11 / 35
0.15.2 11 / 33
0.15.1 11 / 33
0.15.0 11 / 33
0.14.1 11 / 32
0.14.0 10 / 31
0.13.1 9 / 31
0.13.0 9 / 31
0.11.0 9 / 28
0.10.0 9 / 28
0.9.1 9 / 26
0.9.0 9 / 26
0.8.0 6 / 26
0.7.0 6 / 26
0.6.0 6 / 26
0.5.0 6 / 25
0.4.0 6 / 25
0.3.0 6 / 25
0.2.1 6 / 25
0.2.0 6 / 25
0.1.2 6 / 26
0.1.1 6 / 26
0.1.0 6 / 26

v1.4.1

2 findings
HIGH New obfuscated file: dist/locales-DDxq9_IH.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

2 findings
HIGH New obfuscated file: dist/locales-DDxq9_IH.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.2

2 findings
HIGH New obfuscated file: dist/locales-DDxq9_IH.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.1

2 findings
HIGH New obfuscated file: dist/locales-DDxq9_IH.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

2 findings
HIGH New obfuscated file: dist/locales-DDxq9_IH.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.0

2 findings
HIGH New obfuscated file: dist/locales-C7_BArir.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.0

2 findings
HIGH New obfuscated file: dist/locales-C7_BArir.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.2

2 findings
HIGH New obfuscated file: dist/locales-DgSXUfDb.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.1

2 findings
HIGH New obfuscated file: dist/locales-C4VLVD0U.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.0

2 findings
HIGH New obfuscated file: dist/locales-C4VLVD0U.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.1

2 findings
HIGH New obfuscated file: dist/locales-C45uyfCG.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.0

2 findings
HIGH New obfuscated file: dist/locales-DHNt4L1K.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.1

2 findings
HIGH New obfuscated file: dist/locales-DpZYr8Pk.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.0

2 findings
HIGH New obfuscated file: dist/locales-WMT_ybiO.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.0

2 findings
HIGH New obfuscated file: dist/locales-BWBAGbXi.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.0

2 findings
HIGH New obfuscated file: dist/locales-BWBAGbXi.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.1

2 findings
HIGH New obfuscated file: dist/locales-D6myqwkO.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.0

2 findings
HIGH New obfuscated file: dist/locales-D6myqwkO.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

3 findings
HIGH New obfuscated file: dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/locales-C9xR5jDn.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

2 findings
HIGH New obfuscated file: dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.0

2 findings
HIGH New obfuscated file: dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.