← Home

@esri/calcite-components

5
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

noahmulfingerssylviapaulcpedersonpatrickarltodoetomwaysonbenstoltzdbouwmandriskullkatelynseitzrlibedajturnerkellyhutchinsmjuniperjohn4818haoliangmacandcheesejcfrancorichgwozdzrweber.esrivivzhangjuliannemarikdrspacemanphdallieraneykit12303benelanjoerodriguez-136prev8048rbcosbydavidspriggsgowinvannizhangaputtermanbrittneyjbdcdev-npmkri14029gr_e

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/cdn/7DBM34FB.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/6UERLWMH.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/6XE2EP66.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/6ZUCCZI3.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/75ARST2G.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff large-new-source-files AI (source-diff): CDN build output with content-hashed filenames; new files expected on major version bumps. ai
source-diff obfuscated-file:dist/cdn/2I4IL7KB.js AI (source-diff): Minified CDN build output for UI components; not obfuscated malware. ai
source-diff obfuscated-file:dist/cdn/2P5ISR6V.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/2TVQXBLD.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/2VKTPJWO.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/3GDRQKT2.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/3IM4BLOF.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/4A2BNZJW.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/4ANP3V6G.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/4V5C3DSP.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/54WP47EN.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/5C72Z4LQ.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/5SDZUEAZ.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/5ULM4EXU.js AI (source-diff): Minified CDN build output for UI components. ai
source-diff obfuscated-file:dist/cdn/6U4CYHVA.js AI (source-diff): Minified CDN build output for UI components. ai
phantom-deps phantom-dep:@types/sortablejs AI (phantom-deps): @types/sortablejs is a type definition package loaded by convention in TypeScript projects; phantom detection is expected and benign here. ai
phantom-deps phantom-dep:@floating-ui/utils AI (phantom-deps): @floating-ui/utils is referenced via config in this component library; phantom detection is a false positive for this package. ai
license uncommon-license:SEE LICENSE.md AI (license): Esri products consistently use a custom proprietary license referenced as 'SEE LICENSE.md'; this is expected and stable for all versions of this package. ai
phantom-deps phantom-dep:interactjs AI (phantom-deps): interactjs is a declared runtime dependency used via config/build tooling in this large component library; phantom detection is a false positive for this package. ai

Versions (showing 5 of 5)

Version Deps Published
5.1.1 15 / 8
5.1.0 15 / 8
5.0.2 15 / 7
5.0.1 15 / 7
5.0.0 15 / 7

v5.1.1

37 findings
HIGH New obfuscated file: dist/cdn/2JJ5YBBT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/2P3LOGHK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/34ENIUR5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/44HFP2I6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/44VCOKJX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/47Q2AE5B.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/4UHTWXNV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/524MMG22.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/5D7IEY6J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/5VAPN2S2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/5X2CR2NN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cdn/5X2CR2NN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/cdn/6S3G75WP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/6V3FX2W2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/6VDGKXTH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/6VP3K6WL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/7B4FOF3S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/7QS3Z4ZJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/A6V4I2J3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/ALLL4LZ4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/BCRYMNH7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/BSMPD6VA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/C462ZIJD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/C4DW27AP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/CDNETLLO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/CENYPZ3Y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/CEWOZ7LP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/CM45J66U.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/COXLBEPM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/CVJBK7K3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/DDUIHGBF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/DK3SDSZL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/E6X6BQLH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/E7GXKIIO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/ECVX7SVS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/ELXBBUY5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.0

26 findings
HIGH New obfuscated file: dist/cdn/2I4IL7KB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/2P5ISR6V.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/2TVQXBLD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/2VKTPJWO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/3GDRQKT2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/3IM4BLOF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/4A2BNZJW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/4ANP3V6G.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/4V5C3DSP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/54WP47EN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/5C72Z4LQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/5SDZUEAZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/5ULM4EXU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/6U4CYHVA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/6UERLWMH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/6XE2EP66.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/6ZUCCZI3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/75ARST2G.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/7DBM34FB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/7XMGNOPQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/A5L2Q32C.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/ADH55C3C.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/AFGFN5LE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/BL4CROY4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cdn/BPVUFU5U.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.