@wix/design-system
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a common implicit runtime dep for TypeScript packages; stable false positive. | ai | |
| phantom-deps | phantom-dep:globals | AI (phantom-deps): Referenced in config files only; expected for a large build-tool-heavy package. | ai | |
| phantom-deps | phantom-dep:chart.js | AI (phantom-deps): Used via react-chartjs-2 wrapper; indirect usage pattern is expected. | ai | |
| phantom-deps | phantom-dep:popper.js | AI (phantom-deps): Used via react-popper; indirect usage is expected for this design system. | ai | |
| phantom-deps | phantom-dep:@floating-ui/core | AI (phantom-deps): Transitive dep of @floating-ui/react; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-dom-instance | AI (phantom-deps): Declared as direct dep; phantom-dep heuristic misfires on indirect import patterns. | ai | |
| phantom-deps | phantom-dep:react-remove-scroll | AI (phantom-deps): Used transitively; stable false positive for this design system. | ai | |
| phantom-deps | phantom-dep:@wix/design-system-tokens | AI (phantom-deps): Same-org package used via CSS/build tooling; not a direct JS import but legitimately declared. | ai | |
| provenance | no-provenance | AI (provenance): Wix CI publisher with clean track record; provenance absence is common and not a risk signal here. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 1.288.0 | 56 / 126 | |
| 1.287.0 | 56 / 126 | |
| 1.286.0 | 56 / 126 | |
| 1.285.0 | 56 / 126 | |
| 1.284.0 | 56 / 126 | |
| 1.283.0 | 56 / 126 | |
| 1.282.0 | 55 / 126 | |
| 1.281.0 | 55 / 126 | |
| 1.280.1 | 55 / 126 | |
| 1.280.0 | 55 / 126 | |
| 1.279.0 | 55 / 126 | |
| 1.278.0 | 55 / 124 | |
| 1.276.0 | 55 / 124 | |
| 1.274.0 | 55 / 124 | |
| 1.272.0 | 55 / 124 |
v1.288.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.287.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.286.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.285.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.284.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.283.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.282.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.281.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.280.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.280.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.279.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.278.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.276.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.274.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.