← Home

@dxos/react-ui-table

26
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

richburdonmarik_dwittjosiahdxos-botmykola-vrmchk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@dxos/react-client AI (dependencies): First-party DXOS monorepo package, same release version. ai
dependencies unvetted-dep:@dxos/react-ui-data AI (dependencies): First-party DXOS monorepo package, same release version. ai
publish-pattern new-deps-added AI (publish-pattern): Monorepo refactor adding sibling packages, not third-party supply chain risk. ai
provenance publisher-changed AI (provenance): DXOS monorepo migrated CI publisher from dxos-bot to GitHub Actions; SLSA attestation confirms legitimate CI/CD pipeline. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with org-wide CI migration; package has SLSA provenance and is part of a large established monorepo. ai
phantom-deps phantom-dep:@dxos/react-ui-types AI (phantom-deps): Same-org dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@radix-ui/react-slot AI (phantom-deps): Declared dependency; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@fluentui/react-tabster AI (phantom-deps): Declared dependency; phantom-dep heuristic false positive. ai
bogus-package bogus-package AI (bogus-package): Established DXOS monorepo component; sparse README is typical for internal packages. ai
phantom-deps phantom-dep:@dxos/react-ui-searchlist AI (phantom-deps): Same-org dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@radix-ui/react-primitive AI (phantom-deps): Declared dependency; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@radix-ui/react-use-controllable-state AI (phantom-deps): Declared dependency; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@radix-ui/react-context AI (phantom-deps): Declared dependency; phantom-dep heuristic false positive. ai
provenance no-provenance AI (provenance): DXOS publishes 1800+ versions without provenance; consistent pattern across the org. ai
phantom-deps phantom-dep:date-fns AI (phantom-deps): date-fns is a declared dependency; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@dxos/debug AI (phantom-deps): Same-org dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@dxos/react-ui-stack AI (phantom-deps): Same-org dep; phantom-dep heuristic false positive for monorepo packages. ai

Versions (showing 26 of 26)

Version Deps Published
0.9.0 36 / 16
0.8.3 37 / 17
0.8.2 36 / 17
0.7.1 32 / 13
0.7.0 32 / 13
0.6.13 19 / 12
0.6.12 19 / 12
0.6.11 19 / 12
0.6.10 19 / 12
0.6.9 19 / 12
0.6.8 19 / 12
0.6.7 19 / 12
0.6.6 19 / 12
0.6.5 19 / 12
0.6.4 19 / 12
0.6.3 19 / 12
0.6.2 19 / 12
0.6.1 19 / 12
0.6.0 19 / 12
0.5.8 19 / 12
0.5.7 19 / 12
0.5.6 19 / 12
0.5.5 19 / 12
0.5.4 19 / 12
0.5.3 19 / 13
0.5.2 19 / 13

v0.7.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.