← Home

@commercetools-frontend/ui-kit

4
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tdeekensemmenkocommercetools-admin

Keywords

javascripttypescriptdesign-systemreactuikit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@commercetools-uikit/selectable-search-input AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/view-switcher AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/collapsible-panel AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/primary-action-dropdown AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/link AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/fields AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/inputs AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/buttons AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/pagination AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/collapsible AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/field-errors AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/progress-bar AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
dependencies unvetted-dep:@commercetools-uikit/quick-filters AI (dependencies): First-party monorepo sub-package; always published alongside this package at matching version. ai
phantom-deps phantom-dep:@babel/runtime-corejs3 AI (phantom-deps): Same as @babel/runtime — framework-scoped, not directly imported by convention. ai
phantom-deps phantom-dep:@commercetools-uikit/selectable-search-input AI (phantom-deps): Referenced in config files only; stable false positive for this monorepo preset package. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Babel runtime is a framework-level transitive dep, not directly imported by convention; stable false positive for this package. ai

Versions (showing 4 of 4)

Version Deps Published
20.5.0 41 / 5
20.4.0 41 / 5
20.3.1 41 / 5
20.0.0 41 / 5

v20.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v20.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v20.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v20.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.