@icanbwell/composite
@icanbwell/composite. repo version: 0.1336.3
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:233.index.js | AI (source-diff): Webpack chunk bundle with semver/UI code; minification is expected for this UI component library. | ai | |
| source-diff | obfuscated-file:897.index.js | AI (source-diff): Webpack chunk bundle with TypeScript helpers; minification is expected for this UI component library. | ai | |
| source-diff | net-exec-file:233.index.js | AI (source-diff): Network+exec pattern is from webpack chunk loader boilerplate, not dropper malware. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Fires in bundled third-party code (PostCSS/rrweb); stable false positive for this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Fires in bundled rrweb/PostCSS code; not malicious, stable false positive for this package. | ai | |
| source-diff | obfuscated-file:414.index.js | AI (source-diff): Standard webpack chunk bundle with accompanying .map file; consistent with this package's build pipeline across versions. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires in bundled third-party code (regex/template engine); not attacker-controlled input. Stable pattern for this package. | ai | |
| source-diff | encoded-string-file:index.js | AI (source-diff): Long strings are minified React/Apollo/FHIR bundle code, not obfuscated payloads; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@icanbwell/native-components | AI (phantom-deps): Same-org dependency declared for native subpath export; not a direct import by design. | ai |
Versions (showing 65 of 265)
| Version | Deps | Published |
|---|---|---|
| 1.1039.4 | 1 / 0 | |
| 1.1039.3 | 1 / 0 | |
| 1.1039.2 | 1 / 0 | |
| 1.1039.1 | 1 / 0 | |
| 1.1039.0 | 1 / 0 | |
| 1.1038.0 | 1 / 0 | |
| 1.1037.0 | 1 / 0 | |
| 1.1036.1 | 1 / 0 | |
| 1.1036.0 | 1 / 0 | |
| 1.1035.1 | 1 / 0 | |
| 1.1035.0 | 1 / 0 | |
| 1.1034.0 | 1 / 0 | |
| 1.1033.0 | 1 / 0 | |
| 1.1032.2 | 1 / 0 | |
| 1.1032.1 | 1 / 0 | |
| 1.1032.0 | 1 / 0 | |
| 1.1031.0 | 1 / 0 | |
| 1.1030.0 | 1 / 0 | |
| 1.1029.1 | 1 / 0 | |
| 1.620.1 | 1 / 0 | |
| 1.620.0 | 1 / 0 | |
| 1.619.2 | 1 / 0 | |
| 1.619.1 | 1 / 0 | |
| 1.619.0 | 1 / 0 | |
| 1.618.0 | 1 / 0 | |
| 1.617.0 | 1 / 0 | |
| 1.616.1 | 1 / 0 | |
| 1.616.0 | 1 / 0 | |
| 1.615.0 | 1 / 0 | |
| 1.614.0 | 1 / 0 | |
| 1.613.0 | 1 / 0 | |
| 1.612.0 | 1 / 0 | |
| 1.611.1 | 1 / 0 | |
| 1.611.0 | 1 / 0 | |
| 1.610.1 | 1 / 0 | |
| 1.610.0 | 1 / 0 | |
| 1.609.0 | 1 / 0 | |
| 1.608.0 | 1 / 0 | |
| 1.607.0 | 1 / 0 | |
| 1.606.0 | 1 / 0 | |
| 1.605.0 | 1 / 0 | |
| 1.604.1 | 1 / 0 | |
| 1.604.0 | 1 / 0 | |
| 1.603.3 | 1 / 0 | |
| 1.603.2 | 1 / 0 | |
| 1.603.1 | 1 / 0 | |
| 1.603.0 | 1 / 0 | |
| 1.602.0 | 1 / 0 | |
| 1.601.0 | 1 / 0 | |
| 1.600.1 | 1 / 0 | |
| 1.600.0 | 1 / 0 | |
| 1.599.3 | 1 / 0 | |
| 1.599.2 | 1 / 0 | |
| 1.599.1 | 1 / 0 | |
| 1.599.0 | 1 / 0 | |
| 1.598.2 | 1 / 0 | |
| 1.598.1 | 1 / 0 | |
| 1.598.0 | 1 / 0 | |
| 1.597.0 | 1 / 0 | |
| 1.596.1 | 1 / 0 | |
| 1.596.0 | 1 / 0 | |
| 1.595.0 | 1 / 0 | |
| 1.594.0 | 1 / 0 | |
| 1.593.0 | 1 / 0 | |
| 1.589.6 | 1 / 0 |
v1.1039.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1039.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1039.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1039.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1039.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1038.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1037.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1036.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1036.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1035.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1035.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1034.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1033.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1032.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1032.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1032.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1031.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1030.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1029.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.620.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.620.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.619.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.619.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.619.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.618.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.617.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.616.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.616.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.615.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.614.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.613.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.612.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.611.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.611.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.610.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.610.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.609.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.608.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.607.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.606.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.605.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.604.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.604.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.603.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.603.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.603.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.603.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.602.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.601.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.600.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.600.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.599.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.599.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.599.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.599.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.598.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.598.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.598.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.597.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.596.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.596.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.595.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.594.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.593.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.589.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.