@fluentui/react-menu
Fluent UI menu component
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Fluent UI component packages document via external docs/Storybook; short README and no keywords are expected for this ecosystem, not spam indicators. | ai | |
| provenance | no-provenance | AI (provenance): Established Microsoft Fluent UI package; lack of Sigstore provenance is common and not a risk signal for this well-known publisher. | ai | |
| dependencies | unvetted-dep:@griffel/react | AI (dependencies): Griffel is Microsoft's CSS-in-JS library, part of the Fluent UI ecosystem. Unvetted status reflects pipeline gap, not real risk. | ai | |
| dependencies | unvetted-dep:@fluentui/react-aria | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-icons | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-theme | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-motion | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-portal | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/keyboard-keys | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-tabster | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-utilities | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-jsx-runtime | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-positioning | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-shared-contexts | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-context-selector | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai | |
| dependencies | unvetted-dep:@fluentui/react-motion-components-preview | AI (dependencies): First-party Fluent UI sibling package from Microsoft; unvetted status is a pipeline gap. | ai |
Versions (showing 100 of 185)
| Version | Deps | Published |
|---|---|---|
| 9.25.1 | 15 / 0 | |
| 9.25.0 | 15 / 0 | |
| 9.24.1 | 15 / 0 | |
| 9.24.0 | 15 / 0 | |
| 9.23.1 | 15 / 0 | |
| 9.23.0 | 15 / 0 | |
| 9.22.0 | 15 / 0 | |
| 9.21.2 | 13 / 0 | |
| 9.21.1 | 13 / 0 | |
| 9.21.0 | 13 / 0 | |
| 9.20.6 | 13 / 6 | |
| 9.20.5 | 13 / 6 | |
| 9.20.4 | 13 / 6 | |
| 9.20.3 | 13 / 6 | |
| 9.20.2 | 13 / 6 | |
| 9.20.1 | 13 / 6 | |
| 9.20.0 | 13 / 6 | |
| 9.19.6 | 13 / 6 | |
| 9.19.5 | 13 / 6 | |
| 9.19.4 | 13 / 6 | |
| 9.19.3 | 13 / 6 | |
| 9.19.2 | 13 / 6 | |
| 9.19.1 | 13 / 6 | |
| 9.19.0 | 13 / 6 | |
| 9.18.0 | 13 / 6 | |
| 9.17.6 | 13 / 6 | |
| 9.17.5 | 13 / 6 | |
| 9.17.4 | 13 / 6 | |
| 9.17.3 | 13 / 6 | |
| 9.17.2 | 13 / 6 | |
| 9.17.1 | 13 / 6 | |
| 9.17.0 | 13 / 6 | |
| 9.16.9 | 13 / 6 | |
| 9.16.8 | 13 / 6 | |
| 9.16.7 | 13 / 6 | |
| 9.16.6 | 13 / 6 | |
| 9.16.5 | 13 / 6 | |
| 9.16.4 | 13 / 6 | |
| 9.16.3 | 13 / 6 | |
| 9.16.2 | 13 / 6 | |
| 9.16.1 | 13 / 6 | |
| 9.16.0 | 13 / 6 | |
| 9.15.0 | 13 / 6 | |
| 9.14.26 | 13 / 6 | |
| 9.14.25 | 13 / 6 | |
| 9.14.24 | 13 / 6 | |
| 9.14.23 | 13 / 6 | |
| 9.14.22 | 13 / 6 | |
| 9.14.21 | 13 / 6 | |
| 9.14.20 | 13 / 6 | |
| 9.14.19 | 13 / 6 | |
| 9.14.18 | 13 / 7 | |
| 9.14.17 | 13 / 7 | |
| 9.14.16 | 13 / 7 | |
| 9.14.15 | 13 / 7 | |
| 9.14.14 | 13 / 7 | |
| 9.14.13 | 13 / 7 | |
| 9.14.12 | 13 / 7 | |
| 9.14.11 | 13 / 7 | |
| 9.14.10 | 13 / 7 | |
| 9.14.9 | 13 / 7 | |
| 9.14.8 | 13 / 7 | |
| 9.14.7 | 13 / 7 | |
| 9.14.6 | 13 / 6 | |
| 9.14.5 | 13 / 6 | |
| 9.14.4 | 13 / 6 | |
| 9.14.3 | 13 / 6 | |
| 9.14.2 | 13 / 6 | |
| 9.14.1 | 13 / 6 | |
| 9.14.0 | 13 / 6 | |
| 9.13.7 | 13 / 6 | |
| 9.13.6 | 13 / 6 | |
| 9.13.5 | 13 / 6 | |
| 9.13.4 | 13 / 6 | |
| 9.13.3 | 13 / 6 | |
| 9.13.2 | 13 / 6 | |
| 9.13.1 | 13 / 6 | |
| 9.13.0 | 13 / 6 | |
| 9.12.50 | 13 / 6 | |
| 9.12.49 | 13 / 6 | |
| 9.12.48 | 13 / 6 | |
| 9.12.47 | 13 / 6 | |
| 9.12.46 | 13 / 6 | |
| 9.12.45 | 13 / 6 | |
| 9.12.44 | 13 / 6 | |
| 9.12.43 | 13 / 6 | |
| 9.12.42 | 13 / 6 | |
| 9.12.41 | 13 / 6 | |
| 9.12.40 | 13 / 6 | |
| 9.12.39 | 13 / 6 | |
| 9.12.38 | 13 / 6 | |
| 9.12.37 | 13 / 6 | |
| 9.12.36 | 13 / 6 | |
| 9.12.35 | 13 / 6 | |
| 9.12.34 | 13 / 6 | |
| 9.12.33 | 13 / 6 | |
| 9.12.32 | 13 / 6 | |
| 9.12.31 | 13 / 6 | |
| 9.12.30 | 13 / 6 | |
| 9.12.29 | 13 / 6 |
v9.16.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.14.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.14.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.13.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.13.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.13.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.13.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.13.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.13.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.13.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.13.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.12.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.