← Home

@blocklet/uploader

blocklet upload component

51
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

wangshijungxw

Keywords

blockletuploader

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@lottiefiles/react-lottie-player AI (dependencies): Popular Lottie animation React player; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/dashboard AI (dependencies): Well-known Uppy dashboard UI; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/drag-drop AI (dependencies): Well-known Uppy plugin; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/file-input AI (dependencies): Well-known Uppy plugin; stable ecosystem package. ai
dependencies unvetted-dep:@blocklet/ui-react AI (dependencies): Same org (arcblock/blocklet); expected internal dependency. ai
dependencies unvetted-dep:@uppy/image-editor AI (dependencies): Well-known Uppy plugin; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/progress-bar AI (dependencies): Well-known Uppy plugin; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/provider-views AI (dependencies): Well-known Uppy plugin; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/golden-retriever AI (dependencies): Well-known Uppy plugin; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/status-bar AI (dependencies): Well-known Uppy plugin; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/drop-target AI (dependencies): Well-known Uppy plugin; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/tus AI (dependencies): Well-known Uppy file upload library; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/url AI (dependencies): Well-known Uppy plugin; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/core AI (dependencies): Well-known Uppy core library; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/react AI (dependencies): Well-known Uppy React integration; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/webcam AI (dependencies): Well-known Uppy plugin; stable ecosystem package. ai
dependencies unvetted-dep:react-player AI (dependencies): Popular React media player component; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/locales AI (dependencies): Well-known Uppy locales package; stable ecosystem package. ai
dependencies unvetted-dep:@uppy/unsplash AI (dependencies): Well-known Uppy plugin; stable ecosystem package. ai
phantom-deps phantom-dep:react-player AI (phantom-deps): react-player is a declared dependency; phantom-dep is a false positive for this package. ai
phantom-deps phantom-dep:@uppy/file-input AI (phantom-deps): Declared dependency; phantom-dep is a false positive for this package. ai
phantom-deps phantom-dep:@uppy/progress-bar AI (phantom-deps): Declared dependency; phantom-dep is a false positive for this package. ai
phantom-deps phantom-dep:@uppy/golden-retriever AI (phantom-deps): Declared dependency; phantom-dep is a false positive for this package. ai
phantom-deps phantom-dep:ufo AI (phantom-deps): Declared dependency; phantom-dep is a false positive for this package. ai
phantom-deps phantom-dep:@mui/utils AI (phantom-deps): Declared dependency; phantom-dep is a false positive for this package. ai
phantom-deps phantom-dep:mime-types AI (phantom-deps): Declared dependency; phantom-dep is a false positive for this package. ai
provenance no-provenance AI (provenance): Established org package; lack of provenance is common and not a risk signal here. ai

Versions (showing 51 of 52)

View all versions
Version Deps Published
0.15.4 36 / 15
0.3.20 35 / 15
0.3.19 35 / 15
0.3.18 35 / 15
0.3.17 35 / 15
0.3.16 35 / 15
0.3.15 35 / 15
0.3.14 35 / 15
0.3.13 35 / 15
0.3.12 35 / 15
0.3.11 35 / 15
0.3.10 35 / 15
0.3.9 35 / 15
0.3.8 35 / 15
0.3.7 35 / 15
0.3.6 35 / 15
0.3.5 35 / 15
0.3.4 35 / 15
0.3.3 35 / 15
0.3.2 35 / 15
0.3.1 35 / 15
0.3.0 35 / 15
0.2.15 35 / 15
0.2.14 35 / 15
0.2.13 35 / 15
0.2.12 35 / 15
0.2.11 35 / 15
0.2.10 35 / 15
0.2.9 35 / 15
0.2.8 35 / 15
0.2.7 34 / 14
0.2.6 34 / 14
0.2.5 34 / 14
0.2.4 34 / 14
0.2.3 34 / 14
0.2.2 34 / 14
0.2.1 34 / 14
0.2.0 34 / 14
0.1.97 34 / 14
0.1.96 34 / 14
0.1.95 34 / 14
0.1.94 34 / 14
0.1.93 34 / 14
0.1.92 34 / 14
0.1.91 34 / 14
0.1.90 34 / 14
0.1.89 34 / 14
0.1.88 34 / 14
0.1.87 34 / 14
0.1.86 34 / 14
0.1.85 34 / 14

v0.15.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.97

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.96

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.95

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.94

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.93

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.92

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.91

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.90

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.89

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.88

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.87

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.86

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.85

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.