@contractspec/lib.ui-kit-web
Web UI components with Radix primitives
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Scoped monorepo package; description omission is common in internal component libraries. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo component; empty main and missing description are artifacts of build/publish process, not malware indicators. | ai | |
| provenance | no-provenance | AI (provenance): Provenance is not yet standard practice; stable for this package. | ai | |
| phantom-deps | phantom-dep:echarts | AI (phantom-deps): Config-referenced optional dependency; stable for this package. | ai | |
| phantom-deps | phantom-dep:next | AI (phantom-deps): Config-referenced peer dependency; stable pattern for Next.js UI kit. | ai | |
| phantom-deps | phantom-dep:next-themes | AI (phantom-deps): Config-referenced peer dependency; stable for Next.js UI kit. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-context-menu | AI (phantom-deps): Config-referenced component dependency; stable for UI kit. | ai | |
| dependencies | unvetted-dep:@radix-ui/react-hover-card | AI (dependencies): Radix UI is a well-known, trusted component library; stable false positive for this UI kit package. | ai | |
| dependencies | unvetted-dep:@radix-ui/react-avatar | AI (dependencies): Radix UI is a well-known, trusted component library; stable false positive for this UI kit package. | ai | |
| phantom-deps | phantom-dep:@contractspec/lib.contracts-spec | AI (phantom-deps): Same-org dep; phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:tailwind-merge | AI (phantom-deps): Config-file reference in a UI kit; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:lucide-react | AI (phantom-deps): Config-file reference in a UI kit; stable false positive for this package. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 3.13.4 | 41 / 20 | |
| 3.13.3 | 41 / 20 | |
| 3.13.2 | 41 / 20 | |
| 3.13.1 | 41 / 19 | |
| 3.11.0 | 41 / 19 | |
| 3.10.1 | 47 / 14 | |
| 3.10.0 | 47 / 14 | |
| 3.0.0 | 44 / 14 | |
| 1.46.2 | 42 / 15 | |
| 1.46.1 | 42 / 15 | |
| 1.46.0 | 42 / 15 | |
| 1.45.0 | 42 / 15 |
v3.13.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.13.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.46.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.45.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.