@botpress/webchat
A fully customizable React library that lets you seamlessly integrate Botpress Webchat into your React applications.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:react-scroll-to-bottom | AI (phantom-deps): Bundled build; used but not scannable via static import. | ai | |
| phantom-deps | phantom-dep:event-source-polyfill | AI (phantom-deps): Polyfill used conditionally, common false positive. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-avatar | AI (phantom-deps): UI component lib used in webchat widget. | ai | |
| phantom-deps | phantom-dep:react-textarea-autosize | AI (phantom-deps): UI component lib used in webchat widget. | ai | |
| phantom-deps | phantom-dep:@redux-devtools/extension | AI (phantom-deps): Dev-tooling dependency, no malicious use. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-collapsible | AI (phantom-deps): UI component lib used in webchat widget. | ai | |
| phantom-deps | phantom-dep:embla-carousel-react | AI (phantom-deps): UI lib for widget component, bundled build obscures import. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-scroll-area | AI (phantom-deps): UI component lib used in webchat widget. | ai | |
| phantom-deps | phantom-dep:tailwind-merge | AI (phantom-deps): Bundled build hides imports; standard Tailwind utility used across React UI code. | ai | |
| phantom-deps | phantom-dep:@emoji-mart/data | AI (phantom-deps): Bundled build hides imports; used for emoji picker feature. | ai | |
| phantom-deps | phantom-dep:@emoji-mart/react | AI (phantom-deps): Bundled build hides imports; used for emoji picker feature. | ai | |
| phantom-deps | phantom-dep:use-stick-to-bottom | AI (phantom-deps): Bundled build hides imports; standard chat scroll-to-bottom hook. | ai | |
| phantom-deps | phantom-dep:motion | AI (phantom-deps): Bundled build hides imports; motion is a legit animation lib used in this UI package. | ai | |
| phantom-deps | phantom-dep:remark-breaks | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:react-dropzone | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:react-markdown | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:qs | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:@types/deep-equal | AI (phantom-deps): Type-only package; stable false positive for this bundled package. | ai | |
| phantom-deps | phantom-dep:@floating-ui/react | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:exponential-backoff | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:swr | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:mime | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:dayjs | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:nanoid | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:@types/qs | AI (phantom-deps): Type-only package; stable false positive for this bundled package. | ai | |
| phantom-deps | phantom-dep:react-use | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:deep-equal | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:theme-colors | AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 5.3.2 | 41 / 31 | |
| 4.5.2 | 36 / 31 | |
| 4.5.1 | 36 / 31 | |
| 4.5.0 | 36 / 31 | |
| 4.4.9 | 36 / 31 | |
| 4.4.8 | 36 / 31 | |
| 4.4.7 | 36 / 31 | |
| 4.4.6 | 36 / 31 | |
| 4.4.5 | 36 / 31 | |
| 4.4.4 | 36 / 31 | |
| 4.4.3 | 37 / 31 | |
| 4.4.2 | 37 / 31 | |
| 4.4.1 | 37 / 31 | |
| 4.4.0 | 37 / 31 | |
| 4.3.2 | 36 / 33 | |
| 4.2.2 | 36 / 33 | |
| 4.2.1 | 36 / 33 | |
| 4.2.0 | 36 / 35 | |
| 4.1.0 | 36 / 33 | |
| 4.0.4 | 36 / 33 | |
| 4.0.3 | 36 / 33 | |
| 4.0.2 | 36 / 32 | |
| 4.0.1 | 36 / 32 | |
| 4.0.0 | 36 / 32 | |
| 3.2.12 | 36 / 32 |
v5.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.