@babylonlabs-io/core-ui
Supply chain provenance
Status for the latest visible version.
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Manual publish variance, no behavioral indicator; established package with long clean history. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Diff spans 67 versions of accumulated growth, not a sudden injection. | ai | |
| phantom-deps | phantom-dep:react-popper | AI (phantom-deps): Declared in dependencies; used as a re-exported or peer-consumed dep in this UI library. | ai | |
| phantom-deps | phantom-dep:react-tooltip | AI (phantom-deps): Declared in dependencies; used as a re-exported or peer-consumed dep in this UI library. | ai | |
| phantom-deps | phantom-dep:decimal.js-light | AI (phantom-deps): Declared in dependencies; used as a re-exported or peer-consumed dep in this UI library. | ai | |
| phantom-deps | phantom-dep:@hookform/resolvers | AI (phantom-deps): Declared in dependencies; used as a re-exported or peer-consumed dep in this UI library. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 1.106.0 | 7 / 39 | |
| 1.105.0 | 7 / 39 | |
| 1.103.0 | 7 / 39 | |
| 1.102.0 | 7 / 39 | |
| 1.101.1 | 7 / 39 | |
| 1.101.0 | 7 / 39 | |
| 1.100.0 | 7 / 39 | |
| 1.99.0 | 7 / 39 | |
| 1.98.0 | 7 / 39 | |
| 1.97.0 | 7 / 39 | |
| 1.96.0 | 7 / 39 | |
| 1.95.0 | 7 / 39 | |
| 1.94.0 | 7 / 39 | |
| 1.93.0 | 7 / 39 | |
| 1.92.0 | 7 / 39 | |
| 1.91.0 | 7 / 39 | |
| 1.90.4 | 7 / 39 | |
| 1.90.3 | 7 / 39 | |
| 1.90.2 | 7 / 39 | |
| 1.90.1 | 7 / 39 | |
| 1.90.0 | 7 / 39 | |
| 1.88.0 | 7 / 39 | |
| 1.87.2 | 7 / 39 | |
| 1.87.1 | 7 / 39 | |
| 1.87.0 | 7 / 39 | |
| 1.86.0 | 7 / 39 | |
| 1.85.0 | 7 / 39 | |
| 1.69.0 | 7 / 39 | |
| 1.68.0 | 7 / 39 | |
| 1.67.1 | 7 / 39 | |
| 1.67.0 | 7 / 39 | |
| 1.0.0 | 5 / 35 |
v1.106.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.105.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.103.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.102.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.101.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.101.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.69.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: filippos47.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.68.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: filippos47.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.67.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: filippos47.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.67.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: filippos47.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.