@ant-design/agentic-ui
面向智能体的 UI 组件库,提供多步推理可视化、工具调用展示、任务执行协同等 Agentic UI 能力
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/History/components/HistoryEmptyIcon.js | AI (source-diff): Compiled SVG/JSX component with a long attribute line, not real obfuscation. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @galacean/effects is a legitimate animation lib matching package's UI/animation feature set. | ai | |
| dependencies | unvetted-dep:markdown-it | AI (dependencies): markdown-it is a well-known, widely-used markdown parser; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@galacean/effects | AI (dependencies): Galacean Effects is a legitimate animation/effects library from Alibaba; consistent with this UI package's feature set. | ai | |
| provenance | no-provenance | AI (provenance): Established ant-design publisher; lack of provenance is common and not a risk signal here. | ai | |
| phantom-deps | phantom-dep:markdown-it | AI (phantom-deps): Optional markdown dep; config-referenced, not directly imported in all paths. | ai | |
| phantom-deps | phantom-dep:@types/three | AI (phantom-deps): Type-only dep for optional 3D integration; framework-scoped, stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped runtime dep; loaded by convention in transpiled output. | ai | |
| phantom-deps | phantom-dep:tailwind-merge | AI (phantom-deps): Optional styling utility; config-referenced only. | ai | |
| phantom-deps | phantom-dep:styled-components | AI (phantom-deps): Optional styling dep; config-referenced, not required for all consumers. | ai | |
| phantom-deps | phantom-dep:@react-three/fiber | AI (phantom-deps): Optional 3D integration; config-referenced only. | ai | |
| phantom-deps | phantom-dep:three | AI (phantom-deps): Optional 3D integration dep; referenced in config, not required at runtime for all consumers. | ai | |
| phantom-deps | phantom-dep:markdown-it-container | AI (phantom-deps): Optional markdown plugin; config-referenced only. | ai | |
| phantom-deps | phantom-dep:react-resizable-panels | AI (phantom-deps): Optional layout dep; config-referenced only. | ai | |
| phantom-deps | phantom-dep:@juggle/resize-observer | AI (phantom-deps): Optional polyfill; config-referenced only. | ai | |
| phantom-deps | phantom-dep:@better-scroll/scroll-bar | AI (phantom-deps): Optional scroll plugin; config-referenced only. | ai | |
| phantom-deps | phantom-dep:@better-scroll/mouse-wheel | AI (phantom-deps): Optional scroll plugin; config-referenced only. | ai | |
| phantom-deps | phantom-dep:@better-scroll/observe-dom | AI (phantom-deps): Optional scroll plugin; config-referenced only. | ai | |
| phantom-deps | phantom-dep:@better-scroll/core | AI (phantom-deps): Optional scroll dep; config-referenced only. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Large UI lib; lodash-es is the primary import, lodash listed for compat; stable false positive. | ai | |
| phantom-deps | phantom-dep:flubber | AI (phantom-deps): Optional animation dep for chart components; config-referenced only. | ai | |
| phantom-deps | phantom-dep:direction | AI (phantom-deps): Optional RTL utility; config-referenced, not a runtime requirement for all consumers. | ai | |
| phantom-deps | phantom-dep:quicklink | AI (phantom-deps): Optional prefetch dep; config-referenced only. | ai |
Versions (showing 100 of 158)
| Version | Deps | Published |
|---|---|---|
| 2.32.46 | 79 / 49 | |
| 2.32.45 | 79 / 49 | |
| 2.32.44 | 79 / 49 | |
| 2.32.43 | 79 / 49 | |
| 2.32.42 | 79 / 49 | |
| 2.32.41 | 79 / 49 | |
| 2.32.40 | 79 / 49 | |
| 2.32.39 | 79 / 49 | |
| 2.32.38 | 79 / 49 | |
| 2.32.37 | 79 / 49 | |
| 2.32.36 | 79 / 49 | |
| 2.32.35 | 79 / 49 | |
| 2.32.34 | 79 / 49 | |
| 2.32.33 | 79 / 49 | |
| 2.32.32 | 79 / 49 | |
| 2.32.31 | 79 / 49 | |
| 2.32.30 | 79 / 49 | |
| 2.32.28 | 79 / 49 | |
| 2.32.27 | 79 / 49 | |
| 2.32.26 | 79 / 49 | |
| 2.32.25 | 79 / 49 | |
| 2.32.24 | 79 / 49 | |
| 2.32.23 | 79 / 49 | |
| 2.32.21 | 79 / 49 | |
| 2.32.20 | 79 / 49 | |
| 2.32.18 | 79 / 49 | |
| 2.32.17 | 79 / 49 | |
| 2.32.16 | 79 / 49 | |
| 2.32.14 | 79 / 49 | |
| 2.32.13 | 79 / 49 | |
| 2.32.12 | 79 / 49 | |
| 2.32.11 | 79 / 49 | |
| 2.32.10 | 79 / 49 | |
| 2.32.9 | 79 / 49 | |
| 2.32.7 | 79 / 49 | |
| 2.32.6 | 79 / 49 | |
| 2.32.5 | 79 / 49 | |
| 2.32.4 | 78 / 49 | |
| 2.32.3 | 78 / 49 | |
| 2.32.2 | 78 / 49 | |
| 2.32.1 | 78 / 49 | |
| 2.32.0 | 78 / 49 | |
| 2.31.5 | 78 / 50 | |
| 2.31.4 | 78 / 50 | |
| 2.31.3 | 78 / 50 | |
| 2.31.2 | 78 / 50 | |
| 2.31.1 | 78 / 50 | |
| 2.31.0 | 78 / 50 | |
| 2.30.33 | 78 / 50 | |
| 2.30.31 | 78 / 50 | |
| 2.30.30 | 78 / 50 | |
| 2.30.29 | 78 / 50 | |
| 2.30.28 | 78 / 50 | |
| 2.30.27 | 78 / 50 | |
| 2.30.26 | 78 / 50 | |
| 2.30.25 | 78 / 50 | |
| 2.30.24 | 78 / 50 | |
| 2.30.23 | 78 / 50 | |
| 2.30.22 | 78 / 50 | |
| 2.30.21 | 78 / 50 | |
| 2.30.20 | 78 / 50 | |
| 2.30.19 | 78 / 50 | |
| 2.30.17 | 78 / 50 | |
| 2.30.15 | 78 / 50 | |
| 2.30.14 | 78 / 50 | |
| 2.30.13 | 78 / 50 | |
| 2.30.12 | 78 / 50 | |
| 2.30.11 | 78 / 50 | |
| 2.30.10 | 78 / 50 | |
| 2.30.9 | 78 / 50 | |
| 2.30.8 | 78 / 50 | |
| 2.30.7 | 77 / 50 | |
| 2.30.6 | 77 / 50 | |
| 2.30.5 | 77 / 50 | |
| 2.30.4 | 77 / 50 | |
| 2.30.3 | 77 / 50 | |
| 2.30.1 | 76 / 49 | |
| 2.29.57 | 75 / 49 | |
| 2.29.55 | 75 / 49 | |
| 2.29.53 | 72 / 49 | |
| 2.29.49 | 72 / 49 | |
| 2.29.46 | 72 / 49 | |
| 2.29.43 | 72 / 49 | |
| 2.29.41 | 72 / 49 | |
| 2.29.38 | 72 / 49 | |
| 2.29.36 | 71 / 49 | |
| 2.29.33 | 71 / 49 | |
| 2.29.30 | 71 / 49 | |
| 2.29.27 | 71 / 49 | |
| 2.29.26 | 71 / 49 | |
| 2.29.24 | 74 / 50 | |
| 2.29.23 | 74 / 50 | |
| 2.29.19 | 74 / 50 | |
| 2.29.16 | 74 / 50 | |
| 2.29.11 | 74 / 49 | |
| 2.29.10 | 74 / 49 | |
| 2.29.7 | 74 / 49 | |
| 2.29.5 | 74 / 49 | |
| 2.29.4 | 74 / 49 | |
| 2.29.1 | 66 / 46 |
v2.32.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.31.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.31.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.31.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.30.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.30.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.30.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.30.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.30.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.30.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.30.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.30.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.30.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.30.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.57
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.55
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.53
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.49
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.46
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.43
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.41
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.38
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.36
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.33
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.30
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.27
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.26
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.24
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.23
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ranranup123) than the most recent previously approved version (chenshuai2144) on 2026-02-04, but ranranup123 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.29.19
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.16
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.11
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.10
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.7
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ranranup123) than the most recent previously approved version (chenshuai2144) on 2026-01-07, but ranranup123 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.29.4
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.