@cube-dev/ui-kit
UIKit for Cube Projects
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Thin metadata but established, trusted publisher with large track record. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Dev-tool script (icon generator) uses child_process locally, not runtime exfil. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Consistent with legit tooling/testing expansion; no malicious behavior evidenced. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Local git config command, no network/exec of fetched code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Babel helper deps added for build tooling, established packages. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Large feature/version jump in a mature monorepo package, not injected payload evidence. | ai | |
| dependencies | unvetted-dep:@sparticuz/chromium | AI (dependencies): Well-known headless chromium binding used for PDF/screenshot tooling, not malicious. | ai | |
| phantom-deps | phantom-dep:@storybook/test | AI (phantom-deps): Storybook test util referenced in config, not a runtime import; benign. | ai | |
| phantom-deps | phantom-dep:@trivago/prettier-plugin-sort-imports | AI (phantom-deps): Formatter plugin; not a runtime import. | ai | |
| phantom-deps | phantom-dep:@sparticuz/chromium | AI (phantom-deps): Headless browser for testing/screenshots; not a runtime import. | ai | |
| phantom-deps | phantom-dep:globals | AI (phantom-deps): Build/config tooling declared in deps but not imported at runtime; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Doc/config tooling; not a runtime import. | ai | |
| phantom-deps | phantom-dep:serve-handler | AI (phantom-deps): Dev server tooling; not a runtime import. | ai | |
| phantom-deps | phantom-dep:playwright-core | AI (phantom-deps): Test tooling; not a runtime import. | ai | |
| phantom-deps | phantom-dep:typescript-eslint | AI (phantom-deps): Linting tooling; not a runtime import. | ai | |
| phantom-deps | phantom-dep:@vitejs/plugin-react | AI (phantom-deps): Build tooling; not a runtime import. | ai | |
| phantom-deps | phantom-dep:@ianvs/prettier-plugin-sort-imports | AI (phantom-deps): Formatter plugin; not a runtime import. | ai | |
| phantom-deps | phantom-dep:react-types | AI (phantom-deps): Declared dep used in config/type context; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-keyed-flatten-children | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@react-aria/selection | AI (phantom-deps): React Aria packages used transitively; stable false positive. | ai | |
| phantom-deps | phantom-dep:@react-stately/utils | AI (phantom-deps): React Stately utility used transitively; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-focus-lock | AI (phantom-deps): UI kit dependency used indirectly; stable false positive. | ai | |
| phantom-deps | phantom-dep:@react-aria/i18n | AI (phantom-deps): React Aria packages often used transitively; stable false positive. | ai | |
| phantom-deps | phantom-dep:usehooks-ts | AI (phantom-deps): Likely re-exported or used indirectly; stable false positive for this UI kit. | ai |
Versions (showing 51 of 327)
| Version | Deps | Published |
|---|---|---|
| 0.147.3 | 32 / 57 | |
| 0.147.2 | 32 / 57 | |
| 0.147.1 | 32 / 57 | |
| 0.147.0 | 32 / 57 | |
| 0.146.1 | 32 / 57 | |
| 0.146.0 | 32 / 57 | |
| 0.145.4 | 30 / 57 | |
| 0.145.3 | 30 / 57 | |
| 0.145.2 | 30 / 57 | |
| 0.145.1 | 30 / 57 | |
| 0.145.0 | 30 / 57 | |
| 0.144.0 | 30 / 57 | |
| 0.143.1 | 30 / 57 | |
| 0.143.0 | 30 / 57 | |
| 0.142.10 | 30 / 69 | |
| 0.142.9 | 30 / 69 | |
| 0.142.8 | 30 / 69 | |
| 0.142.7 | 30 / 69 | |
| 0.142.6 | 30 / 69 | |
| 0.142.5 | 30 / 69 | |
| 0.142.4 | 30 / 69 | |
| 0.142.3 | 30 / 69 | |
| 0.142.2 | 30 / 69 | |
| 0.142.1 | 30 / 69 | |
| 0.142.0 | 30 / 69 | |
| 0.141.0 | 30 / 69 | |
| 0.140.1 | 30 / 69 | |
| 0.140.0 | 30 / 69 | |
| 0.139.0 | 30 / 69 | |
| 0.138.6 | 30 / 69 | |
| 0.138.5 | 30 / 69 | |
| 0.138.4 | 30 / 69 | |
| 0.138.3 | 30 / 69 | |
| 0.138.2 | 30 / 69 | |
| 0.138.1 | 30 / 69 | |
| 0.138.0 | 30 / 69 | |
| 0.137.1 | 29 / 68 | |
| 0.137.0 | 29 / 68 | |
| 0.136.1 | 29 / 68 | |
| 0.136.0 | 29 / 68 | |
| 0.135.1 | 29 / 67 | |
| 0.135.0 | 29 / 67 | |
| 0.134.0 | 29 / 67 | |
| 0.133.0 | 29 / 67 | |
| 0.132.0 | 29 / 67 | |
| 0.131.0 | 29 / 67 | |
| 0.130.0 | 29 / 67 | |
| 0.129.0 | 30 / 68 | |
| 0.128.0 | 30 / 68 | |
| 0.127.3 | 30 / 68 | |
| 0.127.2 | 30 / 68 |
v0.147.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.147.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.147.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.147.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.146.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.146.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.145.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.145.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.145.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.145.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.145.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.144.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.143.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.143.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.142.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.131.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.130.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.129.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.128.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.127.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.127.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.