← Home

@botpress/webchat

A fully customizable React library that lets you seamlessly integrate Botpress Webchat into your React applications.

25
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

slvnperronbotpress-cloud-opsfranklevasseurmichael.massonpaul.chevilleydavid-ferland

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:react-scroll-to-bottom AI (phantom-deps): Bundled build; used but not scannable via static import. ai
phantom-deps phantom-dep:event-source-polyfill AI (phantom-deps): Polyfill used conditionally, common false positive. ai
phantom-deps phantom-dep:@radix-ui/react-avatar AI (phantom-deps): UI component lib used in webchat widget. ai
phantom-deps phantom-dep:react-textarea-autosize AI (phantom-deps): UI component lib used in webchat widget. ai
phantom-deps phantom-dep:@redux-devtools/extension AI (phantom-deps): Dev-tooling dependency, no malicious use. ai
phantom-deps phantom-dep:@radix-ui/react-collapsible AI (phantom-deps): UI component lib used in webchat widget. ai
phantom-deps phantom-dep:embla-carousel-react AI (phantom-deps): UI lib for widget component, bundled build obscures import. ai
phantom-deps phantom-dep:@radix-ui/react-scroll-area AI (phantom-deps): UI component lib used in webchat widget. ai
phantom-deps phantom-dep:tailwind-merge AI (phantom-deps): Bundled build hides imports; standard Tailwind utility used across React UI code. ai
phantom-deps phantom-dep:@emoji-mart/data AI (phantom-deps): Bundled build hides imports; used for emoji picker feature. ai
phantom-deps phantom-dep:@emoji-mart/react AI (phantom-deps): Bundled build hides imports; used for emoji picker feature. ai
phantom-deps phantom-dep:use-stick-to-bottom AI (phantom-deps): Bundled build hides imports; standard chat scroll-to-bottom hook. ai
phantom-deps phantom-dep:motion AI (phantom-deps): Bundled build hides imports; motion is a legit animation lib used in this UI package. ai
phantom-deps phantom-dep:remark-breaks AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:react-dropzone AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:react-markdown AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:qs AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:@types/deep-equal AI (phantom-deps): Type-only package; stable false positive for this bundled package. ai
phantom-deps phantom-dep:@floating-ui/react AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:exponential-backoff AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:@headlessui/react AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:swr AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:mime AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:axios AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:dayjs AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:nanoid AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:@types/qs AI (phantom-deps): Type-only package; stable false positive for this bundled package. ai
phantom-deps phantom-dep:react-use AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:deep-equal AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:remark-gfm AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai
phantom-deps phantom-dep:theme-colors AI (phantom-deps): Bundled UI library; deps compiled into dist, not directly imported at module level. ai

Versions (showing 25 of 25)

Version Deps Published
5.3.2 41 / 31
4.5.2 36 / 31
4.5.1 36 / 31
4.5.0 36 / 31
4.4.9 36 / 31
4.4.8 36 / 31
4.4.7 36 / 31
4.4.6 36 / 31
4.4.5 36 / 31
4.4.4 36 / 31
4.4.3 37 / 31
4.4.2 37 / 31
4.4.1 37 / 31
4.4.0 37 / 31
4.3.2 36 / 33
4.2.2 36 / 33
4.2.1 36 / 33
4.2.0 36 / 35
4.1.0 36 / 33
4.0.4 36 / 33
4.0.3 36 / 33
4.0.2 36 / 32
4.0.1 36 / 32
4.0.0 36 / 32
3.2.12 36 / 32

v5.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.