@automattic/agenttic-ui
UI components for the Agenttic framework
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@wordpress/data | AI (phantom-deps): Config-file reference in component library; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@automattic/agenttic-client | AI (phantom-deps): Same-org dependency; config-file reference pattern consistent with library. | ai | |
| phantom-deps | phantom-dep:@wordpress/i18n | AI (phantom-deps): Config-file reference in component library; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@visx/xychart | AI (phantom-deps): Config-file reference in component library; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@floating-ui/react-dom | AI (phantom-deps): Newly added runtime dep; referenced in config but legitimate floating UI library. | ai | |
| phantom-deps | phantom-dep:use-debounce | AI (phantom-deps): Hook library re-exported from component library; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): React UI library; remark-gfm used in markdown processing, re-exported via config. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Trusted Automattic publisher with 109 approved packages; no material changes in this release. | ai | |
| dependencies | unvetted-dep:@automattic/charts | AI (dependencies): Same-org (@automattic) dependency; low risk for this package. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-scroll-area | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this component library. | ai | |
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): Declared runtime dep used transitively in component library; phantom-dep heuristic fires on config-only references. | ai | |
| phantom-deps | phantom-dep:react-textarea-autosize | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this component library. | ai | |
| phantom-deps | phantom-dep:lucide-react | AI (phantom-deps): Declared runtime dep in a UI component library; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Listed as both dep and peerDep; phantom-dep fires because it's not directly imported in the analyzed entry. | ai | |
| phantom-deps | phantom-dep:class-variance-authority | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this component library. | ai |
Versions (showing 48 of 48)
| Version | Deps | Published |
|---|---|---|
| 0.1.81 | 14 / 27 | |
| 0.1.80 | 14 / 27 | |
| 0.1.79 | 14 / 27 | |
| 0.1.78 | 17 / 25 | |
| 0.1.77 | 17 / 25 | |
| 0.1.76 | 17 / 25 | |
| 0.1.75 | 17 / 25 | |
| 0.1.74 | 17 / 25 | |
| 0.1.73 | 17 / 25 | |
| 0.1.72 | 17 / 25 | |
| 0.1.71 | 17 / 25 | |
| 0.1.70 | 17 / 25 | |
| 0.1.69 | 17 / 25 | |
| 0.1.68 | 17 / 25 | |
| 0.1.67 | 17 / 25 | |
| 0.1.66 | 17 / 25 | |
| 0.1.65 | 17 / 25 | |
| 0.1.64 | 17 / 25 | |
| 0.1.63 | 17 / 25 | |
| 0.1.62 | 17 / 25 | |
| 0.1.61 | 17 / 25 | |
| 0.1.60 | 17 / 25 | |
| 0.1.58 | 17 / 25 | |
| 0.1.57 | 17 / 25 | |
| 0.1.56 | 17 / 25 | |
| 0.1.53 | 17 / 25 | |
| 0.1.52 | 17 / 25 | |
| 0.1.51 | 17 / 25 | |
| 0.1.49 | 17 / 25 | |
| 0.1.48 | 17 / 25 | |
| 0.1.46 | 17 / 25 | |
| 0.1.45 | 17 / 25 | |
| 0.1.44 | 17 / 25 | |
| 0.1.43 | 17 / 25 | |
| 0.1.42 | 17 / 25 | |
| 0.1.41 | 17 / 25 | |
| 0.1.40 | 17 / 25 | |
| 0.1.37 | 16 / 25 | |
| 0.1.33 | 16 / 25 | |
| 0.1.32 | 16 / 25 | |
| 0.1.31 | 16 / 25 | |
| 0.1.29 | 16 / 25 | |
| 0.1.25 | 16 / 25 | |
| 0.1.22 | 15 / 25 | |
| 0.1.21 | 15 / 25 | |
| 0.1.2 | 15 / 26 | |
| 0.1.1 | 15 / 26 | |
| 0.1.0 | 15 / 26 |
v0.1.81
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (t2dw4t) than the most recent previously approved version (a8c) on 2026-07-20, but t2dw4t is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.80
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (a8c) than the most recent previously approved version (alshakero) on 2026-07-15, but a8c is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.79
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (alshakero) than the most recent previously approved version (a8c) on 2026-07-15, but alshakero is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.78
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.77
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (a8c) than the most recent previously approved version (saroshaga) on 2026-07-15, but a8c is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.76
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (saroshaga) than the most recent previously approved version (a8c) on 2026-07-15, but saroshaga is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.75
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (a8c) than the most recent previously approved version (iamchughmayank) on 2026-07-13, but a8c is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.74
2 findingsThis version was published by a different npm account than previous versions on 2026-07-09. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.73
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.