← Home

@wix/auto-patterns

React Library flow package generated with Yoshi.

64
Versions
UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

yoavwix-cishahatawixnpmwix-ambassadorwix-ci-publisherwix-bi-publishergalil-teamusability-sessionsyurynixydanivmayacoamitde007haimbrum-wixyoungshinobiethanparielhwix-org-headlessfalconcinadavlacroir-wixdorchaouat

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:draft-js-import-html AI (phantom-deps): Editor support lib, config-referenced. ai
phantom-deps phantom-dep:draft-js AI (phantom-deps): Used via generated/config-referenced code, not a real risk. ai
phantom-deps phantom-dep:immutable AI (phantom-deps): Transitive support lib for draft-js editor stack. ai
phantom-deps phantom-dep:@wix/media AI (phantom-deps): Same-org first-party dep. ai
phantom-deps phantom-dep:@wix/ricos AI (phantom-deps): Same-org first-party dep. ai
phantom-deps phantom-dep:@wix/rich-content AI (phantom-deps): Same-org first-party dep. ai
phantom-deps phantom-dep:draftjs-conductor AI (phantom-deps): Editor support lib, config-referenced. ai
phantom-deps phantom-dep:draft-js-export-html AI (phantom-deps): Editor support lib, config-referenced. ai
maintainer-change maintainer-removed AI (maintainer-change): Internal Wix team roster change under same wix-ci-publisher CI identity. ai
dependencies unvetted-dep:@wix/auto-cms-field-types AI (dependencies): First-party @wix scoped package, consistent with monorepo dependency graph. ai
maintainer-change maintainer-added AI (maintainer-change): Publisher is trusted wix-ci-publisher with long clean history; internal team maintainer addition. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps are established/first-party packages needed for rich content feature. ai
provenance no-provenance AI (provenance): Internal Wix CI publisher; provenance absence is consistent across all versions. ai
bogus-package bogus-package AI (bogus-package): Internal @wix scoped package; sparse metadata is expected for private org tooling. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Declared but not directly imported; stable false positive for this package. ai

Versions (showing 64 of 64)

Version Deps Published
1.63.0 9 / 35
1.62.0 9 / 35
1.61.0 9 / 35
1.60.0 9 / 35
1.59.0 9 / 35
1.58.0 8 / 35
1.57.0 8 / 35
1.56.0 17 / 35
1.55.0 17 / 35
1.54.0 17 / 35
1.53.0 16 / 34
1.52.0 16 / 34
1.51.0 16 / 34
1.50.0 16 / 34
1.49.0 14 / 36
1.48.0 14 / 36
1.47.0 15 / 36
1.46.0 14 / 36
1.45.0 5 / 28
1.44.0 5 / 28
1.43.0 5 / 27
1.42.0 5 / 27
1.41.0 5 / 27
1.40.0 4 / 27
1.39.0 4 / 27
1.38.0 4 / 27
1.37.0 4 / 27
1.36.0 4 / 27
1.35.0 4 / 27
1.34.0 4 / 27
1.33.0 5 / 28
1.32.0 5 / 28
1.31.0 5 / 28
1.30.0 5 / 28
1.29.0 5 / 28
1.28.0 5 / 28
1.27.0 5 / 28
1.26.0 5 / 28
1.25.0 5 / 28
1.24.0 5 / 28
1.23.0 5 / 28
1.22.0 5 / 28
1.21.0 5 / 28
1.20.0 5 / 28
1.19.0 5 / 28
1.18.0 5 / 28
1.17.0 5 / 28
1.16.0 6 / 27
1.15.0 5 / 26
1.14.0 5 / 26
1.13.0 5 / 26
1.12.0 5 / 26
1.11.0 5 / 26
1.10.0 5 / 28
1.9.0 5 / 26
1.8.0 5 / 26
1.7.0 5 / 26
1.6.0 5 / 26
1.5.0 5 / 26
1.4.0 4 / 26
1.3.0 4 / 26
1.2.0 4 / 26
1.1.0 4 / 26
1.0.0 4 / 14

v1.57.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.56.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.55.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.54.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.53.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.52.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.51.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.50.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.49.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.48.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.47.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.46.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.