← Home

sanity

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sanity-svc.npmsanity-io

Keywords

cmscontentheadlessrealtimesanity

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@portabletext/plugin-table AI (dependencies): Official @portabletext scoped package, same family as many existing deps. ai
dependencies unvetted-dep:@sanity/workbench AI (dependencies): First-party Sanity monorepo package, alpha version expected for new feature. ai
phantom-deps phantom-dep:@portabletext/plugin-list-index AI (phantom-deps): Monorepo re-export pattern; false positive typical for this package. ai
phantom-deps phantom-dep:@portabletext/plugin-dnd AI (phantom-deps): Monorepo re-export pattern; false positive typical for this package. ai
source-diff obfuscated-file:lib/_chunks-es/Tool.js AI (source-diff): Bundled ESM build output with readable imports; not obfuscated. Stable for this package. ai
phantom-deps phantom-dep:@isaacs/ttlcache AI (phantom-deps): Config-referenced dependency in monorepo. ai
phantom-deps phantom-dep:exif-component AI (phantom-deps): Config-referenced dependency in monorepo. ai
phantom-deps phantom-dep:@sentry/react AI (phantom-deps): Config-referenced dependency in monorepo. ai
phantom-deps phantom-dep:player.style AI (phantom-deps): Config-referenced dependency in monorepo. ai
phantom-deps phantom-dep:json-reduce AI (phantom-deps): Config-referenced dependency in monorepo. ai
phantom-deps phantom-dep:dataloader AI (phantom-deps): Config-referenced dependency in monorepo. ai
phantom-deps phantom-dep:polished AI (phantom-deps): Config-referenced dependency in monorepo. ai
phantom-deps phantom-dep:color2k AI (phantom-deps): Config-referenced dependency in monorepo. ai
phantom-deps phantom-dep:mendoza AI (phantom-deps): Config-referenced dependency in monorepo. ai
phantom-deps phantom-dep:arrify AI (phantom-deps): Config-referenced dependency in monorepo. ai
phantom-deps phantom-dep:raf AI (phantom-deps): Polyfill loaded by convention in this framework. ai
phantom-deps phantom-dep:jsdom AI (phantom-deps): Used at runtime via require in SSR context; config-referenced. ai
phantom-deps phantom-dep:react-focus-lock AI (phantom-deps): Config-referenced dependency in monorepo. ai
phantom-deps phantom-dep:@types/tar-stream AI (phantom-deps): Type-only package loaded by convention. ai
phantom-deps phantom-dep:@types/shallow-equals AI (phantom-deps): Type-only package loaded by convention. ai
phantom-deps phantom-dep:@types/speakingurl AI (phantom-deps): Type-only package loaded by convention. ai
semgrep semgrep:env-spread AI (semgrep): CLI tool loading env files via Vite's loadEnv; standard config pattern. ai
semgrep semgrep:dynamic-require AI (semgrep): Plugin/module loader pattern; expected for a CLI framework. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): False positive: IP appears inside a user-facing warning message string, not an actual request. ai
semgrep semgrep:env-bulk-read AI (semgrep): Reading PATH env var key cross-platform; standard Node.js pattern. ai
phantom-deps phantom-dep:esbuild AI (phantom-deps): Known implicit binary dependency. ai
phantom-deps phantom-dep:@types/which AI (phantom-deps): Type-only package loaded by convention. ai
phantom-deps phantom-dep:@types/react-is AI (phantom-deps): Type-only package loaded by convention. ai
phantom-deps phantom-dep:@types/use-sync-external-store AI (phantom-deps): Type-only package loaded by convention. ai
phantom-deps phantom-dep:@portabletext/html AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@dnd-kit/utilities AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@date-fns/tz AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@dnd-kit/modifiers AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@dnd-kit/sortable AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:react-refractor AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:web-vitals AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:refractor AI (phantom-deps): Large monorepo package; phantom-dep heuristic unreliable for bundled/re-exported deps. ai
phantom-deps phantom-dep:classnames AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@sanity/mutate AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@portabletext/plugin-one-line AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@dnd-kit/core AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@sanity/media-library-types AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:use-device-pixel-ratio AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@tanstack/react-table AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@portabletext/to-html AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@portabletext/patches AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:isomorphic-dompurify AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@sanity/eventsource AI (phantom-deps): Stable false positive for this package's build structure. ai
phantom-deps phantom-dep:@sanity/prism-groq AI (phantom-deps): Stable false positive for this package's build structure. ai

Versions (showing 51 of 61)

View all versions
Version Deps Published
6.6.0 106 / 43
6.5.0 105 / 43
6.4.0 105 / 43
6.3.0 104 / 43
6.2.0 101 / 44
6.1.0 101 / 50
6.0.0 101 / 50
5.31.1 101 / 49
5.31.0 101 / 49
5.30.0 101 / 49
5.29.0 101 / 49
5.28.0 101 / 49
5.27.0 101 / 49
5.26.0 101 / 49
5.25.1 101 / 49
5.25.0 101 / 49
5.24.0 101 / 49
5.23.0 101 / 49
5.22.0 101 / 47
5.21.0 101 / 47
5.20.0 101 / 47
5.19.0 101 / 47
5.18.0 101 / 48
5.17.1 101 / 48
5.17.0 101 / 48
5.16.0 100 / 48
5.15.0 100 / 48
5.14.1 148 / 49
5.14.0 148 / 49
5.13.0 148 / 49
5.12.0 148 / 49
5.11.0 148 / 50
5.10.0 148 / 50
5.9.0 148 / 50
5.8.1 148 / 50
5.8.0 148 / 50
5.7.0 146 / 49
5.6.0 143 / 50
5.5.0 142 / 50
5.4.0 141 / 49
5.3.1 141 / 49
5.3.0 141 / 49
5.2.0 143 / 50
5.1.0 143 / 50
5.0.1 143 / 50
5.0.0 144 / 50
4.22.0 145 / 50
4.21.1 145 / 50
4.21.0 145 / 50
4.20.3 145 / 50
4.20.2 145 / 50

v6.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.3.0

2 findings
HIGH New obfuscated file: lib/_chunks-es/Tool.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.24.0

1 finding
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.