smbls
[](https://www.npmjs.com/package/smbls) [](https://www.npmjs.com/package/smbls) [](https://git
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Umbrella/meta package for symbo.ls ecosystem; sparse README is expected for this type of package. | ai | |
| phantom-deps | phantom-dep:@symbo.ls/cli | AI (phantom-deps): First-party scoped dep; config-only reference is expected for CLI tooling in this monorepo. | ai | |
| dependencies | unvetted-dep:@symbo.ls/uikit | AI (dependencies): First-party @symbo.ls scoped dep; stable false positive. | ai | |
| dependencies | unvetted-dep:@symbo.ls/smbls-utils | AI (dependencies): First-party @symbo.ls scoped dep; stable false positive. | ai | |
| dependencies | unvetted-dep:@symbo.ls/fetch | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/state | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/helmet | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/router | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/signal | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/analyze | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:domql | AI (dependencies): First-party ecosystem dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/element | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/scratch | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/polyglot | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/shorthand | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/default-config | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:domql | AI (phantom-deps): domql is a declared runtime dep; phantom-dep is a false positive here. | ai | |
| dependencies | unvetted-dep:@symbo.ls/capsize | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:css-in-props | AI (dependencies): First-party ecosystem dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/css | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@symbo.ls/sync | AI (dependencies): Same-org scoped dep; stable pattern for this package. | ai |
Versions (showing 51 of 130)
| Version | Deps | Published |
|---|---|---|
| 3.14.373 | 0 / 20 | |
| 3.14.343 | 0 / 20 | |
| 3.14.342 | 0 / 20 | |
| 3.14.340 | 0 / 20 | |
| 3.14.339 | 0 / 20 | |
| 3.14.338 | 0 / 20 | |
| 3.14.337 | 0 / 20 | |
| 3.14.336 | 0 / 20 | |
| 3.14.335 | 0 / 20 | |
| 3.14.330 | 0 / 20 | |
| 3.14.328 | 0 / 20 | |
| 3.14.327 | 0 / 20 | |
| 3.14.325 | 0 / 20 | |
| 3.14.319 | 0 / 20 | |
| 3.14.315 | 0 / 20 | |
| 3.14.310 | 0 / 20 | |
| 3.14.307 | 0 / 20 | |
| 3.14.306 | 0 / 20 | |
| 3.14.285 | 0 / 20 | |
| 3.14.279 | 0 / 20 | |
| 3.14.278 | 0 / 20 | |
| 3.14.276 | 0 / 20 | |
| 3.14.275 | 0 / 20 | |
| 3.14.274 | 0 / 20 | |
| 3.14.271 | 0 / 20 | |
| 3.14.270 | 0 / 20 | |
| 3.14.267 | 0 / 20 | |
| 3.14.256 | 0 / 20 | |
| 3.14.255 | 0 / 20 | |
| 3.14.253 | 0 / 20 | |
| 3.14.252 | 0 / 20 | |
| 3.14.251 | 0 / 20 | |
| 3.14.250 | 0 / 20 | |
| 3.14.249 | 0 / 20 | |
| 3.14.247 | 0 / 20 | |
| 3.14.246 | 0 / 20 | |
| 3.14.245 | 0 / 20 | |
| 3.14.242 | 0 / 20 | |
| 3.14.240 | 0 / 20 | |
| 3.14.238 | 0 / 20 | |
| 3.14.237 | 0 / 20 | |
| 3.14.236 | 0 / 20 | |
| 3.14.232 | 0 / 20 | |
| 3.14.228 | 0 / 20 | |
| 3.14.226 | 0 / 20 | |
| 3.14.225 | 0 / 20 | |
| 3.14.222 | 0 / 20 | |
| 3.14.221 | 0 / 20 | |
| 3.14.220 | 0 / 20 | |
| 3.14.219 | 0 / 20 | |
| 3.14.212 | 0 / 20 |
v3.14.373
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.343
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.342
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.340
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.339
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.338
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.337
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.336
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.335
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.330
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.328
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.327
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.325
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.319
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.315
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.310
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.307
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.306
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.285
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.279
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.278
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.276
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.275
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.274
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.271
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.270
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.267
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.256
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.255
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.253
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.252
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.251
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.250
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.249
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.247
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.246
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.245
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.242
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.240
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.238
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.237
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.236
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.232
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.228
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.226
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.225
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.222
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.221
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.220
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.219
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.14.212
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.