← Home

@copilotkit/react-ui

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

copilotkit

Keywords

aiassistantautomationcopilotcopilotkitjavascriptnextjsnodejsreacttextarea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/index.umd.js AI (source-diff): UMD bundle build output for React UI lib; net+exec pattern is bundler boilerplate, stable FP. ai
provenance publisher-changed AI (provenance): Transition from manual publish to GitHub Actions CI/CD with SLSA provenance; legitimate for this org. ai
provenance no-provenance AI (provenance): CopilotKit consistently publishes without provenance; stable pattern across 65 approved packages. ai

Versions (showing 51 of 137)

View all versions
Version Deps Published
1.63.2 10 / 12
1.63.1 10 / 12
1.63.0 10 / 12
1.62.3 10 / 12
1.62.2 10 / 12
1.62.1 10 / 12
1.62.0 10 / 12
1.61.2 10 / 12
1.61.1 10 / 12
1.61.0 9 / 11
1.60.2 9 / 11
1.60.1 9 / 11
1.60.0 9 / 11
1.59.5 9 / 11
1.59.4 9 / 11
1.59.3 9 / 11
1.59.2 9 / 11
1.59.1 9 / 11
1.59.0 9 / 11
1.58.0 9 / 11
1.57.4 9 / 11
1.57.3 9 / 11
1.57.2 9 / 11
1.57.1 9 / 11
1.57.0 9 / 11
1.56.5 9 / 11
1.56.4 9 / 11
1.56.3 9 / 11
1.56.2 9 / 11
1.56.1 9 / 11
1.56.0 9 / 11
1.55.3 9 / 11
1.55.2 9 / 11
1.55.1 9 / 11
1.55.0 9 / 11
1.54.1 9 / 12
1.54.0 9 / 12
1.53.0 9 / 12
1.52.1 9 / 12
1.52.0 9 / 12
1.51.4 9 / 14
1.51.3 9 / 14
1.51.2 9 / 14
1.51.1 6 / 17
1.51.0 6 / 17
1.50.1 9 / 14
1.50.0 9 / 14
1.10.6 9 / 14
1.10.5 9 / 14
1.10.4 9 / 14
1.10.3 9 / 14

v1.63.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.63.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.63.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.61.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.51.4

2 findings
HIGH New file with network + code execution: dist/index.umd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.51.3

2 findings
HIGH New file with network + code execution: dist/index.umd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.