Complaint Management UI package — atomic React components that run on the parent app's auth and API
A caller-controlled API URL can receive bearer credentials sourced from component props or browser storage. No install-time attack surface was identified.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgThe client accepts a caller-provided API URL and uses it as the HTTP client's base URL.
dist/complaint-app.jsView on unpkg · L3802Requests attach either a provided token or a token read from browser storage as a bearer credential.
dist/complaint-app.jsView on unpkg · L3815Complaint data requests use that configured client.
dist/complaint-app.jsView on unpkg · L4100A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgThe package has no install lifecycle hook; its scripts are development and build commands.
package.jsonView on unpkg · L21This report applies to @attabot/complaint-app@1.0.25.
See version security history for other recorded verdicts.
Evidence last updated: .
The client accepts a caller-provided API URL and uses it as the HTTP client's base URL.
dist/complaint-app.jsView on unpkg · L3802Requests attach either a provided token or a token read from browser storage as a bearer credential.
dist/complaint-app.jsView on unpkg · L3815Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgComplaint data requests use that configured client.
dist/complaint-app.jsView on unpkg · L4100The package has no install lifecycle hook; its scripts are development and build commands.
package.jsonView on unpkg · L21