← Home

@fluentui/react-charts

React web chart controls for Microsoft fluentui v9 system.

10
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

chrisdholtmiroslavstastnylevithomasonuifabricteamuifrnbotlayershifterjustslonemicrosoft1essopranopillow

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@fluentui/chart-utilities AI (dependencies): Same @fluentui org scope as this package; part of the official Microsoft FluentUI monorepo. ai
phantom-deps phantom-dep:@types/d3-time AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-array AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-color AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-scale AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-shape AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-format AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-axis AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-hierarchy AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-selection AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-time-format AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:d3-hierarchy AI (phantom-deps): d3-hierarchy is a standard d3 sub-module used by charting libs; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@fluentui/react-jsx-runtime AI (phantom-deps): Same-org FluentUI package; used via JSX transform convention, not direct import. ai
bogus-package bogus-package AI (bogus-package): Microsoft FluentUI component library; README link-dump signal is a false positive for official MS docs style. ai
phantom-deps phantom-dep:@types/d3-sankey AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai

Versions (showing 10 of 10)

Version Deps Published
9.3.18 34 / 0
9.3.16 34 / 0
9.2.1 34 / 4
9.2.0 34 / 4
9.1.10 34 / 5
9.1.4 34 / 5
9.1.3 34 / 5
9.1.1 34 / 5
9.0.6 34 / 5
9.0.5 34 / 5

v9.3.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.3.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.