← Home

@dxos/react-ui-attention

Signifier components and providers for attention system.

10
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

richburdonmarik_dwittjosiahdxos-botmykola-vrmchk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): DXOS org migrated publishing from dxos-bot to GitHub Actions CI; SLSA attestation confirms legitimate automated pipeline. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with org-level CI migration; SLSA provenance attestation confirms supply chain integrity. ai
phantom-deps phantom-dep:@dxos/echo AI (phantom-deps): Same org scope (@dxos); likely re-exported or used indirectly via monorepo barrel imports. ai
phantom-deps phantom-dep:@radix-ui/react-menu AI (phantom-deps): Radix UI transitive dep referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:@dxos/log AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic is a stable false positive for this package. ai
phantom-deps phantom-dep:@radix-ui/react-use-controllable-state AI (phantom-deps): Radix UI transitive dep referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:@radix-ui/react-compose-refs AI (phantom-deps): Radix UI transitive dep referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:@dxos/echo-schema AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic is a stable false positive for this package. ai
phantom-deps phantom-dep:@radix-ui/primitive AI (phantom-deps): Radix UI transitive dep referenced in config; stable false positive for this package. ai

Versions (showing 10 of 10)

Version Deps Published
0.9.0 15 / 9
0.8.3 15 / 10
0.8.2 15 / 11
0.8.1 11 / 11
0.8.0 11 / 11
0.7.4 11 / 11
0.7.3 11 / 11
0.7.2 10 / 11
0.7.1 10 / 11
0.7.0 10 / 11

v0.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.