← Home

@boostxyz/widgets

- 🛠️ Test-driven - 🌎 I18n-ready - 🤲 WAI-ARIA compliant

20
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

moimikeyccashwelljamieboostquaziasammccord

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@boostxyz/boost-ui AI (phantom-deps): Same-org dependency listed in package.json dependencies; phantom detection likely reflects indirect import pattern in this monorepo-style package. ai
provenance publisher-changed AI (provenance): jamieboost is a same-org publisher with strong track record (31 approved/0 rejected); transition from moimikey appears to be a legitimate internal handoff within the @boostxyz organization. ai
phantom-deps phantom-dep:@boostxyz/sdk AI (phantom-deps): Same-org dependency listed in package.json dependencies; phantom detection likely reflects indirect import pattern in this monorepo-style package. ai
dependencies unvetted-dep:@boostxyz/boost-ui AI (dependencies): @boostxyz/boost-ui is part of the same @boostxyz ecosystem published by the same trusted publisher; stable false positive. ai
phantom-deps phantom-dep:@tanstack/react-query AI (phantom-deps): Referenced in config files only; minor packaging hygiene issue, not a security concern for this package. ai
phantom-deps phantom-dep:@vanilla-extract/css AI (phantom-deps): Referenced in config files only; minor packaging hygiene issue, not a security concern for this package. ai
dependencies unvetted-dep:@tanstack/react-query AI (dependencies): @tanstack/react-query is a widely-used, well-maintained React data-fetching library with no security concerns; stable false positive for this package. ai
dependencies unvetted-dep:@vanilla-extract/css AI (dependencies): @vanilla-extract/css is a well-known CSS-in-JS library; no security concerns, stable false positive for this package. ai
provenance no-provenance AI (provenance): Publisher has a clean track record; lack of provenance is common and not a disqualifier for this established package. ai

Versions (showing 20 of 20)

Version Deps Published
0.3.1 4 / 29
0.3.0 4 / 28
0.2.15 4 / 28
0.2.14 4 / 28
0.2.13 4 / 28
0.2.12 4 / 28
0.2.11 4 / 28
0.2.10 4 / 28
0.2.9 4 / 28
0.2.8 4 / 28
0.2.7 4 / 28
0.2.6 4 / 28
0.2.5 4 / 28
0.2.4 4 / 28
0.2.3 4 / 28
0.2.2 4 / 28
0.2.1 4 / 27
0.2.0 4 / 27
0.1.0 4 / 27
0.0.2 2 / 27