@douyinfe/semi-ui-19
A modern, comprehensive, flexible design system and UI library. Connect DesignOps & DevOps. Quickly build beautiful React apps. Maintained by Douyin-fe team. (React 19 Compatible)
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() used in a Proxy trap for global config defaults — standard JS pattern, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@douyinfe/semi-theme-default | AI (phantom-deps): Same-org package, likely a peer/optional dep for theming. | ai | |
| phantom-deps | phantom-dep:@douyinfe/semi-animation-react | AI (phantom-deps): Same-org package, consistent with large component library structure. | ai | |
| phantom-deps | phantom-dep:date-fns-tz | AI (phantom-deps): Referenced in config files only; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:jsonc-parser | AI (phantom-deps): Config-file reference only; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:utility-types | AI (phantom-deps): Type-only dependency; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-mention | AI (phantom-deps): Optional rich-text editor integration; config-file reference only. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 2.100.0 | 36 / 40 | |
| 2.99.3 | 36 / 40 | |
| 2.99.2 | 36 / 40 | |
| 2.99.1 | 36 / 40 | |
| 2.99.0 | 36 / 40 | |
| 2.97.0 | 36 / 40 | |
| 2.96.0 | 36 / 40 |
v2.100.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.99.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.99.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.99.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.99.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.97.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.