← Home

@dxos/react-ui-pickers

A collection of picker components.

6
Versions
MIT
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

richburdonmarik_dwittjosiahdxos-botmykola-vrmchk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): DXOS org migrated CI publishing from dxos-bot to GitHub Actions; SLSA attestation confirms CI/CD provenance. ai
phantom-deps phantom-dep:emoji-mart AI (phantom-deps): emoji-mart is a peer/config dependency of @emoji-mart packages; not directly imported but legitimately declared. ai
phantom-deps phantom-dep:@dxos/react-ui-types AI (phantom-deps): Monorepo sibling; phantom-dep heuristic unreliable for bundled packages. ai
phantom-deps phantom-dep:@dxos/log AI (phantom-deps): Monorepo sibling; phantom-dep heuristic unreliable for bundled packages. ai
bogus-package bogus-package AI (bogus-package): Internal DXOS component library; sparse README and no keywords are expected for org-internal packages. ai
phantom-deps phantom-dep:react-resize-detector AI (phantom-deps): Referenced in config files; legitimate transitive use in a bundled package. ai
phantom-deps phantom-dep:@dxos/util AI (phantom-deps): Monorepo sibling; phantom-dep heuristic unreliable for bundled packages. ai

Versions (showing 6 of 6)

Version Deps Published
0.10.0 8 / 8
0.9.0 8 / 8
0.8.3 8 / 8
0.8.2 8 / 8
0.8.1 7 / 8
0.8.0 5 / 8

v0.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.