@fluentui/react-menu
Fluent UI menu component
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Fluent UI component packages document via external docs/Storybook; short README and no keywords are expected for this ecosystem, not spam indicators. | ai | |
| provenance | no-provenance | AI (provenance): Established Microsoft Fluent UI package; lack of Sigstore provenance is common and not a risk signal for this well-known publisher. | ai | |
| dependencies | unvetted-dep:@griffel/react | AI (dependencies): Griffel is Microsoft's CSS-in-JS library, part of the Fluent UI ecosystem. Unvetted status reflects pipeline gap, not real risk. | ai | |
| dependencies | unvetted-dep:@fluentui/react-aria | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-icons | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-theme | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-motion | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-portal | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/keyboard-keys | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-tabster | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-utilities | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-jsx-runtime | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-positioning | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-shared-contexts | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-context-selector | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-motion-components-preview | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai |
Versions (showing 51 of 185)
| Version | Deps | Published |
|---|---|---|
| 9.25.1 | 15 / 0 | |
| 9.25.0 | 15 / 0 | |
| 9.24.1 | 15 / 0 | |
| 9.24.0 | 15 / 0 | |
| 9.23.1 | 15 / 0 | |
| 9.23.0 | 15 / 0 | |
| 9.22.0 | 15 / 0 | |
| 9.21.2 | 13 / 0 | |
| 9.21.1 | 13 / 0 | |
| 9.21.0 | 13 / 0 | |
| 9.20.6 | 13 / 6 | |
| 9.20.5 | 13 / 6 | |
| 9.20.4 | 13 / 6 | |
| 9.20.3 | 13 / 6 | |
| 9.20.2 | 13 / 6 | |
| 9.20.1 | 13 / 6 | |
| 9.20.0 | 13 / 6 | |
| 9.19.6 | 13 / 6 | |
| 9.19.5 | 13 / 6 | |
| 9.19.4 | 13 / 6 | |
| 9.19.3 | 13 / 6 | |
| 9.19.2 | 13 / 6 | |
| 9.19.1 | 13 / 6 | |
| 9.19.0 | 13 / 6 | |
| 9.18.0 | 13 / 6 | |
| 9.17.6 | 13 / 6 | |
| 9.17.5 | 13 / 6 | |
| 9.17.4 | 13 / 6 | |
| 9.17.3 | 13 / 6 | |
| 9.17.2 | 13 / 6 | |
| 9.17.1 | 13 / 6 | |
| 9.17.0 | 13 / 6 | |
| 9.16.9 | 13 / 6 | |
| 9.16.8 | 13 / 6 | |
| 9.16.7 | 13 / 6 | |
| 9.16.6 | 13 / 6 | |
| 9.16.5 | 13 / 6 | |
| 9.16.4 | 13 / 6 | |
| 9.16.3 | 13 / 6 | |
| 9.16.2 | 13 / 6 | |
| 9.16.1 | 13 / 6 | |
| 9.16.0 | 13 / 6 | |
| 9.15.0 | 13 / 6 | |
| 9.14.26 | 13 / 6 | |
| 9.14.25 | 13 / 6 | |
| 9.14.24 | 13 / 6 | |
| 9.14.23 | 13 / 6 | |
| 9.14.22 | 13 / 6 | |
| 9.14.21 | 13 / 6 | |
| 9.14.20 | 13 / 6 | |
| 9.14.19 | 13 / 6 |
v9.16.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.