@devexpress/dx-core
Core library for DevExtreme Reactive Components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Long-stable publisher swap within DevExpress org, no malicious behavior. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same handoff event, stable for years on npm. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Publisher change from 2022, unremoved for 1306d, not a takeover pattern. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 4.0.11 | 0 / 15 | |
| 4.0.10 | 0 / 15 | |
| 4.0.9 | 0 / 15 | |
| 4.0.8 | 0 / 15 | |
| 4.0.7 | 0 / 15 | |
| 4.0.6 | 0 / 15 | |
| 4.0.5 | 0 / 15 | |
| 4.0.4 | 0 / 15 | |
| 4.0.3 | 0 / 15 | |
| 4.0.2 | 0 / 15 | |
| 4.0.1 | 0 / 15 | |
| 4.0.0 | 0 / 15 |
v4.0.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.8
2 findingsThis version was published by a different npm account (timbset) than the most recent previously approved version (yuliya.smirnova) on 2024-02-05. It has since remained available on npm for 900 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.7
2 findingsThis version was published by a different npm account (timbset) than the most recent previously approved version (yuliya.smirnova) on 2024-01-30. It has since remained available on npm for 906 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.6
2 findingsThis version was published by a different npm account (timbset) than the most recent previously approved version (yuliya.smirnova) on 2023-11-06. It has since remained available on npm for 991 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.5
2 findingsThis version was published by a different npm account (timbset) than the most recent previously approved version (yuliya.smirnova) on 2023-07-03. It has since remained available on npm for 1117 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.4
2 findingsThis version was published by a different npm account (timbset) than the most recent previously approved version (yuliya.smirnova) on 2023-05-17. It has since remained available on npm for 1164 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.3
2 findingsThis version was published by a different npm account (timbset) than the most recent previously approved version (yuliya.smirnova) on 2023-01-27. It has since remained available on npm for 1274 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.2
2 findingsThis version was published by a different npm account (timbset) than the most recent previously approved version (yuliya.smirnova) on 2022-12-26. It has since remained available on npm for 1306 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1
2 findingsThis version was published by a different npm account (timbset) than the most recent previously approved version (yuliya.smirnova) on 2022-12-21. It has since remained available on npm for 1311 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.