← Home

@100mslive/roomkit-react

![Banner](https://github.com/100mslive/web-sdks/blob/06c65259912db6ccd8617f2ecb6fef51429251ec/prebuilt-banner.png)

5
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

yogeshfromhmsaniketbaniket100mseswar-clynnvishal09vivek9patelravitheja83saptanpmsaikatmitra-100ms

Keywords

100mslivereactprebuiltroomkit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:worker-timers AI (dependencies): worker-timers is a legitimate Web Worker timer polyfill; no malicious indicators. ai
phantom-deps phantom-dep:recordrtc AI (phantom-deps): recordrtc is a legitimate declared dependency; phantom-dep heuristic fires because it's not directly imported at top level. ai

Versions (showing 5 of 5)

Version Deps Published
0.5.2 41 / 12
0.5.1 41 / 12
0.5.0 41 / 12
0.4.4 41 / 12
0.4.3 41 / 12

v0.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.