← Home

@workflow/web-shared

Shared components for Workflow Observability UI

14
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

matt.strakavercel-release-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/lib/cn.js AI (source-diff): TS-compiled readable output (tailwind-merge config), not obfuscation. ai
source-diff obfuscated-file:dist/components/ui/context-card.js AI (source-diff): Compiled component source, readable, no obfuscation signature. ai
publish-pattern new-deps-added AI (publish-pattern): Well-known Radix/react-use-measure deps matching new UI component. ai
phantom-deps phantom-dep:shiki AI (phantom-deps): Declared in dependencies; used via config/build tooling, not direct import. Stable FP for this package. ai
phantom-deps phantom-dep:@tailwindcss/postcss AI (phantom-deps): PostCSS plugin; referenced in config, not direct JS import. Stable FP. ai
phantom-deps phantom-dep:date-fns AI (phantom-deps): Declared in dependencies; used via config files. Stable FP for this package. ai
phantom-deps phantom-dep:tailwindcss AI (phantom-deps): CSS build tooling; referenced in config, not direct JS import. Stable FP. ai

Versions (showing 14 of 14)

Version Deps Published
4.1.13 19 / 8
4.1.12 19 / 8
4.1.11 17 / 8
4.1.10 17 / 8
4.1.9 17 / 8
4.1.8 17 / 8
4.1.7 17 / 8
4.1.6 17 / 8
4.1.5 17 / 8
4.1.4 17 / 8
4.1.3 17 / 8
4.1.2 17 / 8
4.1.1 17 / 8
4.1.0 17 / 8

v4.1.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.12

3 findings
HIGH New obfuscated file: dist/lib/cn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/ui/context-card.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.