@djangocfg/ui-core
Pure React UI component library without Next.js dependencies - for Electron, Vite, CRA apps
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): nextjs-toploader is a legitimate, established Next.js utility; no malicious indicators. | ai | |
| dependencies | unvetted-dep:@radix-ui/react-avatar | AI (dependencies): Official Radix UI component; stable, well-known package. | ai | |
| dependencies | unvetted-dep:@radix-ui/react-hover-card | AI (dependencies): Official Radix UI component; stable, well-known package. | ai | |
| dependencies | unvetted-dep:@web3icons/react | AI (dependencies): Legitimate web3 icon library; no malware indicators. | ai | |
| phantom-deps | phantom-dep:@hookform/resolvers | AI (phantom-deps): Likely re-exported or used indirectly in a UI library context. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-toast | AI (phantom-deps): Likely re-exported or used indirectly in a UI library context. | ai | |
| phantom-deps | phantom-dep:i18n-iso-countries | AI (phantom-deps): Likely re-exported or used indirectly in a UI library context. | ai |
Versions (showing 51 of 182)
| Version | Deps | Published |
|---|---|---|
| 2.1.431 | 50 / 8 | |
| 2.1.430 | 50 / 8 | |
| 2.1.429 | 50 / 8 | |
| 2.1.428 | 50 / 8 | |
| 2.1.427 | 50 / 8 | |
| 2.1.426 | 50 / 8 | |
| 2.1.425 | 50 / 8 | |
| 2.1.424 | 50 / 8 | |
| 2.1.423 | 50 / 8 | |
| 2.1.422 | 50 / 8 | |
| 2.1.421 | 50 / 8 | |
| 2.1.420 | 50 / 8 | |
| 2.1.419 | 50 / 8 | |
| 2.1.418 | 50 / 8 | |
| 2.1.417 | 50 / 8 | |
| 2.1.416 | 50 / 8 | |
| 2.1.415 | 50 / 8 | |
| 2.1.413 | 50 / 8 | |
| 2.1.412 | 50 / 8 | |
| 2.1.411 | 50 / 8 | |
| 2.1.409 | 50 / 8 | |
| 2.1.408 | 50 / 8 | |
| 2.1.407 | 49 / 8 | |
| 2.1.404 | 49 / 8 | |
| 2.1.402 | 49 / 8 | |
| 2.1.400 | 49 / 8 | |
| 2.1.399 | 49 / 8 | |
| 2.1.397 | 49 / 8 | |
| 2.1.395 | 49 / 8 | |
| 2.1.394 | 49 / 8 | |
| 2.1.393 | 49 / 8 | |
| 2.1.390 | 49 / 8 | |
| 2.1.389 | 49 / 8 | |
| 2.1.387 | 49 / 8 | |
| 2.1.385 | 49 / 8 | |
| 2.1.384 | 49 / 8 | |
| 2.1.383 | 49 / 8 | |
| 2.1.382 | 49 / 9 | |
| 2.1.381 | 49 / 9 | |
| 2.1.380 | 49 / 9 | |
| 2.1.379 | 49 / 9 | |
| 2.1.378 | 49 / 9 | |
| 2.1.377 | 49 / 9 | |
| 2.1.376 | 49 / 9 | |
| 2.1.375 | 49 / 9 | |
| 2.1.374 | 49 / 9 | |
| 2.1.373 | 49 / 9 | |
| 2.1.372 | 49 / 9 | |
| 2.1.371 | 49 / 9 | |
| 2.1.369 | 49 / 9 | |
| 2.1.368 | 49 / 9 |
v2.1.431
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.430
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.429
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.428
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.427
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.426
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.425
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.424
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.423
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.422
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.421
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.420
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.419
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.418
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.417
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.416
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.415
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.413
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.412
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.411
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.409
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.408
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.407
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.404
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.402
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.400
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.399
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.397
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.395
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.394
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.393
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.390
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.389
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.387
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.385
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.384
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.383
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.382
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.381
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.380
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.379
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.378
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.377
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.376
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.375
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.374
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.373
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.372
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.371
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.369
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.368
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.