← Home

@chakra-ui/slider

Accessible slider component for React that implements <input type=range>

27
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

segunadebayo_codebender828

Keywords

reactchakra uichakracomponentslideraccessiblea11y sliderreact a11y sliderreact accessible sliderreact slidera11yinput rangereact aria sliderariaaria slider

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@chakra-ui/react-types AI (phantom-deps): Same-org monorepo dep, used indirectly via build tooling. ai
phantom-deps phantom-dep:@chakra-ui/react-use-controllable-state AI (phantom-deps): Same-org monorepo dep, used indirectly via build tooling. ai
phantom-deps phantom-dep:@chakra-ui/react-use-update-effect AI (phantom-deps): Same-org monorepo dep, used indirectly via build tooling. ai
phantom-deps phantom-dep:@chakra-ui/react-use-callback-ref AI (phantom-deps): Same-org monorepo dep, used indirectly via build tooling. ai
phantom-deps phantom-dep:@chakra-ui/react-use-merge-refs AI (phantom-deps): Same-org monorepo dep, used indirectly via build tooling. ai
phantom-deps phantom-dep:@chakra-ui/react-use-pan-event AI (phantom-deps): Same-org monorepo dep, used indirectly via build tooling. ai
phantom-deps phantom-dep:@chakra-ui/react-use-size AI (phantom-deps): Same-org monorepo dep, used indirectly via build tooling. ai
phantom-deps phantom-dep:@chakra-ui/react-context AI (phantom-deps): Same-org monorepo dep, used indirectly via build tooling. ai
phantom-deps phantom-dep:@chakra-ui/number-utils AI (phantom-deps): Same-org monorepo dep, used indirectly via build tooling. ai
publish-pattern dormant-publish AI (publish-pattern): Chakra UI packages publish in batches across monorepo; not indicative of takeover. ai
source-diff source-size-dropped AI (source-diff): Registry diff artifact of dist rebuild, not code stub replacement. ai
phantom-deps phantom-dep:@chakra-ui/hooks AI (phantom-deps): Same-org internal dep, re-exported not directly imported. ai
phantom-deps phantom-dep:@chakra-ui/utils AI (phantom-deps): Same-org internal dep, re-exported not directly imported. ai
phantom-deps phantom-dep:@chakra-ui/react-utils AI (phantom-deps): Same-org internal dep, re-exported not directly imported. ai
provenance missing-githead AI (provenance): Monorepo lerna-style publish; consistent with long-trusted publisher history. ai
dependencies unvetted-dep:@chakra-ui/react-use-merge-refs AI (dependencies): Internal Chakra UI monorepo sub-package; stable false positive for this package. ai
dependencies unvetted-dep:@chakra-ui/react-use-latest-ref AI (dependencies): Internal Chakra UI monorepo sub-package; stable false positive for this package. ai
dependencies unvetted-dep:@chakra-ui/react-use-pan-event AI (dependencies): Internal Chakra UI monorepo sub-package; stable false positive for this package. ai
dependencies unvetted-dep:@chakra-ui/react-use-size AI (dependencies): Internal Chakra UI monorepo sub-package; stable false positive for this package. ai
dependencies unvetted-dep:@chakra-ui/react-context AI (dependencies): Internal Chakra UI monorepo sub-package; stable false positive for this package. ai
dependencies unvetted-dep:@chakra-ui/number-utils AI (dependencies): Internal Chakra UI monorepo sub-package; stable false positive for this package. ai
dependencies unvetted-dep:@chakra-ui/react-types AI (dependencies): Internal Chakra UI monorepo sub-package; stable false positive for this package. ai
provenance no-provenance AI (provenance): Chakra UI predates Sigstore provenance; absence is expected for this package. ai
dependencies unvetted-dep:@chakra-ui/react-use-controllable-state AI (dependencies): Internal Chakra UI monorepo sub-package; stable false positive for this package. ai
dependencies unvetted-dep:@chakra-ui/react-use-update-effect AI (dependencies): Internal Chakra UI monorepo sub-package; stable false positive for this package. ai
dependencies unvetted-dep:@chakra-ui/react-use-callback-ref AI (dependencies): Internal Chakra UI monorepo sub-package; stable false positive for this package. ai

Versions (showing 27 of 27)

Version Deps Published
2.1.0 10 / 7
2.0.25 10 / 7
2.0.24 10 / 7
2.0.23 10 / 7
2.0.22 10 / 7
2.0.21 10 / 7
2.0.20 10 / 7
2.0.19 10 / 7
2.0.18 10 / 7
2.0.17 10 / 7
2.0.16 10 / 7
2.0.15 10 / 7
2.0.14 10 / 7
2.0.13 10 / 7
2.0.12 10 / 7
2.0.11 9 / 6
2.0.10 9 / 6
2.0.9 9 / 6
2.0.8 9 / 6
2.0.7 9 / 6
2.0.6 3 / 5
2.0.5 3 / 5
2.0.4 3 / 2
2.0.3 3 / 2
2.0.2 3 / 2
2.0.1 3 / 2
2.0.0 3 / 2

v2.0.24

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.23

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.22

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.21

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.20

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.19

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.18

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.17

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.16

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.15

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.14

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.13

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.12

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.11

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.10

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.9

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.8

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.7

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.6

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.5

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: segunadebayo.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.