← Home

@fluentui/react-charts

React web chart controls for Microsoft fluentui v9 system.

39
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

chrisdholtmiroslavstastnylevithomasonuifabricteamuifrnbotlayershifterjustslonemicrosoft1essopranopillowmicrosoft-oss-releases

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): microsoft-oss-releases is a known MS org release automation account. ai
publish-pattern new-deps-added AI (publish-pattern): d3-color/chart-utilities are legitimate first-party/d3 deps for new chart component. ai
maintainer-change maintainer-removed AI (maintainer-change): Routine maintainer roster churn in large Microsoft monorepo, not a takeover pattern. ai
source-diff large-new-source-files AI (source-diff): New chart components are expected feature growth, not injected code. ai
dependencies unvetted-dep:@fluentui/chart-utilities AI (dependencies): Same @fluentui org scope as this package; part of the official Microsoft FluentUI monorepo. ai
phantom-deps phantom-dep:@types/d3-shape AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-format AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-sankey AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-hierarchy AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-axis AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-time-format AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:d3-hierarchy AI (phantom-deps): d3-hierarchy is a standard d3 sub-module used by charting libs; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@fluentui/react-jsx-runtime AI (phantom-deps): Same-org FluentUI package; used via JSX transform convention, not direct import. ai
bogus-package bogus-package AI (bogus-package): Microsoft FluentUI component library; README link-dump signal is a false positive for official MS docs style. ai
phantom-deps phantom-dep:@types/d3-selection AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-time AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-array AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-color AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/d3-scale AI (phantom-deps): TypeScript @types packages declared as deps in a charting lib; loaded by convention, not direct import. ai

Versions (showing 39 of 39)

Version Deps Published
9.3.22 34 / 0
9.3.21 34 / 0
9.3.20 34 / 0
9.3.19 34 / 0
9.3.18 34 / 0
9.3.17 34 / 0
9.3.16 34 / 0
9.3.15 34 / 0
9.3.14 34 / 0
9.3.12 34 / 0
9.3.11 34 / 0
9.3.10 34 / 0
9.3.9 34 / 0
9.3.8 34 / 4
9.3.7 34 / 4
9.3.6 34 / 4
9.3.5 34 / 4
9.3.4 34 / 4
9.2.1 34 / 4
9.2.0 34 / 4
9.1.10 34 / 5
9.1.9 34 / 5
9.1.8 34 / 5
9.1.7 34 / 5
9.1.6 34 / 5
9.1.5 34 / 5
9.1.4 34 / 5
9.1.3 34 / 5
9.1.2 34 / 5
9.1.1 34 / 5
9.1.0 34 / 5
9.0.7 34 / 5
9.0.6 34 / 5
9.0.5 34 / 5
9.0.4 34 / 5
9.0.3 34 / 5
9.0.2 31 / 5
9.0.1 31 / 5
9.0.0 31 / 5

v9.3.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.