← Home

@ariakit/react

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

diegohazariakit-botbenrodrsdaniguardiola

Keywords

a11yariakitcomponentsreacttoolkitui

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:cjs/__chunks/BRLTDORG.cjs AI (source-diff): esbuild CJS bundle banner, not obfuscation; build output for this package. ai
phantom-deps phantom-dep:@ariakit/core AI (phantom-deps): Same-org dep used in bundled output; not scannable. ai
phantom-deps phantom-dep:@floating-ui/dom AI (phantom-deps): Used via bundled build output with no scannable imports. ai
source-diff obfuscated-file:cjs/index.cjs AI (source-diff): Bundled CJS chunk output, not obfuscation; stable for this package's build. ai
source-diff obfuscated-file:cjs/__chunks/GF35MDH7.cjs AI (source-diff): esbuild bundler output (long minified lines), not obfuscation; expected in this package's dist. ai
source-diff obfuscated-file:cjs/__chunks/LZ6L3ECG.cjs AI (source-diff): Standard CJS bundler output (esbuild __commonJS/__toESM helpers), not obfuscation. ai
source-diff obfuscated-file:cjs/__chunks/7FULUV5L.cjs AI (source-diff): Standard CJS bundle output with long first line; not obfuscation. Stable for this package. ai
source-diff large-new-source-files AI (source-diff): Component library regularly reshuffles CJS chunks across versions. ai
source-diff obfuscated-file:cjs/__chunks/JBOLBTVU.cjs AI (source-diff): Standard CJS bundler output (esbuild helpers), not obfuscation. Stable for this package. ai
source-diff obfuscated-file:cjs/__chunks/QAUJZR6Y.cjs AI (source-diff): Standard CJS bundler output (esbuild helpers), not obfuscation; stable for this package. ai
publish-pattern dormant-publish AI (publish-pattern): Long-lived popular package; dormancy is normal for stable UI libraries. ai
provenance missing-githead AI (provenance): CI environment change; SLSA provenance present, established package with strong ecosystem trust. ai
dependencies unvetted-dep:@ariakit/react-core AI (dependencies): Internal monorepo sibling package; stable false positive for this package family. ai

Versions (showing 51 of 79)

View all versions
Version Deps Published
0.4.35 1 / 2
0.4.34 1 / 2
0.4.33 1 / 2
0.4.32 1 / 2
0.4.31 1 / 2
0.4.30 1 / 2
0.4.29 1 / 2
0.4.28 1 / 2
0.4.27 1 / 2
0.4.26 1 / 2
0.4.25 1 / 2
0.4.24 1 / 2
0.4.23 1 / 0
0.4.22 1 / 0
0.4.21 1 / 0
0.4.20 1 / 0
0.4.19 1 / 0
0.4.18 1 / 0
0.4.17 1 / 0
0.4.16 1 / 0
0.4.15 1 / 0
0.4.14 1 / 0
0.4.13 1 / 0
0.4.12 1 / 0
0.4.11 1 / 0
0.4.10 1 / 0
0.4.9 1 / 0
0.4.8 1 / 0
0.4.7 1 / 0
0.4.6 1 / 0
0.4.5 1 / 0
0.4.4 1 / 0
0.4.3 1 / 0
0.4.2 1 / 0
0.4.1 1 / 0
0.4.0 1 / 0
0.3.14 1 / 0
0.3.13 1 / 0
0.3.12 1 / 0
0.3.11 1 / 0
0.3.10 1 / 0
0.3.9 1 / 0
0.3.8 1 / 0
0.3.7 1 / 0
0.3.6 1 / 0
0.3.5 1 / 0
0.3.4 1 / 0
0.3.3 1 / 0
0.3.2 1 / 0
0.3.1 1 / 0
0.3.0 1 / 0

v0.4.35

2 findings
HIGH New obfuscated file: cjs/__chunks/BRLTDORG.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.33

2 findings
HIGH New obfuscated file: cjs/__chunks/GF35MDH7.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.32

2 findings
HIGH New obfuscated file: cjs/__chunks/LZ6L3ECG.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.31

2 findings
HIGH New obfuscated file: cjs/__chunks/LZ6L3ECG.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.6

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2024-04-23, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2024-04-23, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.5

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2024-03-28, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2024-03-28, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.4

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2024-03-18, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2024-03-18, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.3

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2024-03-07, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2024-03-07, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.2

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2024-03-04, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2024-03-04, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.1

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2024-01-26, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2024-01-26, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.4.0

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2024-01-18, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2024-01-18, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.14

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2024-01-14, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2024-01-14, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.13

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2024-01-10, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2024-01-10, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.12

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-12-30, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-12-30, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.11

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-12-22, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-12-22, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.10

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-12-15, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-12-15, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.9

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-12-09, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-12-09, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.8

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-12-02, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-12-02, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.7

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-11-28, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-11-28, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.6

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-11-21, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-11-21, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.5

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-10-14, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-10-14, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.4

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-10-08, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-10-08, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.3

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-09-26, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-09-26, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.2

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-09-14, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-09-14, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.1

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-09-10, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-09-10, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.0

3 findings
HIGH New obfuscated file: cjs/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: diegohaz → ariakit-bot (on 2023-09-06, known maintainer) provenance

This version was published by a different npm account (ariakit-bot) than the most recent previously approved version (diegohaz) on 2023-09-06, but ariakit-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.