@wordpress/components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:build/card/card/component.cjs | AI (source-diff): esbuild bundled CJS output, not obfuscation; stable build artifact for this package. | ai | |
| source-diff | obfuscated-file:build-module/card/get-padding-by-size.js | AI (source-diff): Bundled emotion CSS with inline sourcemap; long lines are build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/card/get-padding-by-size.js | AI (source-diff): esbuild CJS output of same emotion CSS module; benign build artifact. | ai | |
| source-diff | obfuscated-file:build/navigation/styles/navigation-styles.cjs | AI (source-diff): Standard CJS bundler output with readable source comments; not obfuscated. | ai | |
| source-diff | obfuscated-file:build/date-time/date/styles.cjs | AI (source-diff): Standard CJS bundler output with readable source comments; not obfuscated. | ai | |
| source-diff | obfuscated-file:build/date-time/time/styles.cjs | AI (source-diff): Standard CJS bundler output with readable source comments; not obfuscated. | ai | |
| source-diff | obfuscated-file:build/divider/styles.cjs | AI (source-diff): Standard CJS bundler output with readable source comments; not obfuscated. | ai | |
| source-diff | obfuscated-file:build-types/date-time/time/styles.d.ts | AI (source-diff): TypeScript .d.ts with long generic type signatures, not obfuscation. Stable for this package. | ai | |
| dependencies | unvetted-dep:@wordpress/style-runtime | AI (dependencies): Same-org @wordpress scoped package from the Gutenberg monorepo; consistent with established release pattern. | ai | |
| phantom-deps | phantom-dep:@types/highlight-words-core | AI (phantom-deps): Type-only dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@wordpress/base-styles | AI (phantom-deps): SCSS-only dep consumed via build pipeline, not JS imports; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/gradient-parser | AI (phantom-deps): Type-only dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Type-only dep used by convention in TS projects; not directly imported at runtime. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 37.0.0 | 50 / 14 | |
| 36.1.0 | 50 / 14 | |
| 36.0.1 | 50 / 14 | |
| 36.0.0 | 50 / 14 | |
| 35.0.1 | 51 / 13 | |
| 35.0.0 | 52 / 9 | |
| 34.0.0 | 52 / 9 | |
| 33.1.0 | 50 / 9 | |
| 33.0.0 | 49 / 9 | |
| 32.6.0 | 49 / 9 | |
| 32.5.0 | 49 / 9 | |
| 32.4.0 | 49 / 9 | |
| 32.3.0 | 49 / 9 | |
| 32.2.1 | 49 / 9 | |
| 32.2.0 | 49 / 9 | |
| 32.1.0 | 49 / 9 | |
| 32.0.0 | 48 / 9 | |
| 31.0.0 | 47 / 1 | |
| 30.9.0 | 47 / 1 | |
| 30.8.0 | 46 / 0 | |
| 30.6.5 | 46 / 0 | |
| 30.6.4 | 46 / 0 | |
| 30.6.3 | 46 / 0 | |
| 30.6.2 | 46 / 0 |
v37.0.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (desrosj) than the most recent previously approved version (gutenbergplugin) on 2026-07-14, but desrosj is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v36.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v36.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v32.4.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gutenbergplugin) than the most recent previously approved version (peterwilsoncc) on 2026-03-18, but gutenbergplugin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v32.3.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gutenbergplugin) than the most recent previously approved version (peterwilsoncc) on 2026-03-04, but gutenbergplugin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v32.2.1
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (desrosj) than the most recent previously approved version (gutenbergplugin) on 2026-06-30, but desrosj is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v32.2.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v32.1.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v32.0.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v31.0.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.9.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.8.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.6.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (peterwilsoncc) than the most recent previously approved version (gutenbergplugin) on 2026-01-29, but peterwilsoncc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v30.6.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.6.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v30.6.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.