@fluentui-react-native/framework
Component framework used by fluentui react native controls
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Microsoft-owned package with bot publisher; dormancy reflects active development cycle, not account takeover. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/memo-cache | AI (dependencies): Same-monorepo sibling package from Microsoft FluentUI; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/merge-props | AI (dependencies): Same-monorepo sibling package from Microsoft FluentUI; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/immutable-merge | AI (dependencies): Same-monorepo sibling package from Microsoft FluentUI; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/default-theme | AI (dependencies): Sibling package in the same Microsoft FluentUI React Native monorepo, published by the same trusted bot publisher. No risk. | ai | |
| dependencies | unvetted-peer-dep:@office-iss/react-native-win32 | AI (dependencies): Optional peer dependency for Office Win32 React Native platform; expected for this Microsoft FluentUI package. | ai | |
| provenance | no-provenance | AI (provenance): Established Microsoft monorepo package; lack of Sigstore provenance is common and not a security concern for this publisher. | ai | |
| dependencies | unvetted-peer-dep:react-native-macos | AI (dependencies): Well-known optional platform peer dependency for macOS React Native support; no risk. | ai | |
| dependencies | unvetted-peer-dep:react-native-windows | AI (dependencies): Well-known optional platform peer dependency for Windows React Native support; no risk. | ai |
Versions (showing 51 of 195)
| Version | Deps | Published |
|---|---|---|
| 0.16.0 | 9 / 15 | |
| 0.15.3 | 9 / 19 | |
| 0.15.1 | 9 / 19 | |
| 0.15.0 | 9 / 19 | |
| 0.14.17 | 9 / 13 | |
| 0.14.16 | 9 / 13 | |
| 0.14.15 | 9 / 13 | |
| 0.14.14 | 9 / 13 | |
| 0.14.13 | 9 / 13 | |
| 0.14.12 | 9 / 13 | |
| 0.14.11 | 10 / 10 | |
| 0.14.10 | 10 / 10 | |
| 0.14.9 | 10 / 10 | |
| 0.14.8 | 10 / 10 | |
| 0.14.7 | 10 / 10 | |
| 0.14.6 | 12 / 10 | |
| 0.14.5 | 12 / 10 | |
| 0.14.4 | 12 / 10 | |
| 0.14.3 | 12 / 8 | |
| 0.14.2 | 12 / 7 | |
| 0.14.1 | 12 / 7 | |
| 0.14.0 | 12 / 7 | |
| 0.13.10 | 12 / 6 | |
| 0.13.9 | 12 / 6 | |
| 0.13.8 | 12 / 6 | |
| 0.13.7 | 12 / 6 | |
| 0.13.6 | 12 / 6 | |
| 0.13.5 | 12 / 6 | |
| 0.13.4 | 12 / 6 | |
| 0.13.3 | 12 / 6 | |
| 0.13.2 | 12 / 6 | |
| 0.13.1 | 12 / 6 | |
| 0.13.0 | 12 / 6 | |
| 0.12.0 | 12 / 6 | |
| 0.11.10 | 12 / 5 | |
| 0.11.9 | 12 / 5 | |
| 0.11.8 | 12 / 5 | |
| 0.11.7 | 12 / 5 | |
| 0.11.6 | 12 / 5 | |
| 0.11.5 | 12 / 5 | |
| 0.11.4 | 12 / 5 | |
| 0.11.3 | 12 / 5 | |
| 0.11.2 | 12 / 5 | |
| 0.11.1 | 12 / 5 | |
| 0.11.0 | 12 / 5 | |
| 0.10.0 | 12 / 5 | |
| 0.9.10 | 12 / 6 | |
| 0.9.9 | 12 / 6 | |
| 0.9.8 | 12 / 6 | |
| 0.9.7 | 12 / 6 | |
| 0.9.6 | 12 / 6 |
v0.14.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.14.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.