@fluentui/react-native
A react-native component library that implements the Fluent Design System.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Benign CI metadata change for trusted Microsoft-published package. | ai | |
| phantom-deps | phantom-dep:@uifabricshared/theming-ramp | AI (phantom-deps): Config-referenced dependency; stable pattern for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@fluentui-react-native/tokens | AI (phantom-deps): Platform-specific binary package; expected re-export pattern. | ai | |
| phantom-deps | phantom-dep:@fluentui-react-native/adapters | AI (phantom-deps): Platform-specific binary package; expected re-export pattern. | ai | |
| phantom-deps | phantom-dep:@uifabricshared/immutable-merge | AI (phantom-deps): Config-referenced dependency; stable pattern for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@uifabricshared/foundation-tokens | AI (phantom-deps): Config-referenced dependency; stable pattern for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@uifabricshared/theming-react-native | AI (phantom-deps): Platform-specific binary package; expected re-export pattern. | ai | |
| phantom-deps | phantom-dep:@uifabricshared/foundation-composable | AI (phantom-deps): Config-referenced dependency; stable pattern for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@uifabricshared/foundation-compose | AI (phantom-deps): Config-referenced dependency; stable pattern for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@uifabricshared/foundation-settings | AI (phantom-deps): Config-referenced dependency; stable pattern for this monorepo package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/shimmer | AI (dependencies): Sibling package in same monorepo/org, consistent with existing dep pattern. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Routine addition of same-org component library, low risk. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/link | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai | |
| provenance | no-provenance | AI (provenance): Microsoft's automated bot publisher for this monorepo does not currently attach Sigstore provenance; consistent across all versions and not a risk signal for this package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/text | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/button | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/callout | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/persona | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/tablist | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/checkbox | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/separator | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/menu-button | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/radio-group | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/persona-coin | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai | |
| dependencies | unvetted-dep:@fluentui-react-native/contextual-menu | AI (dependencies): First-party sub-package from the same microsoft/fluentui-react-native monorepo; published in lockstep with the umbrella package. | ai |
Versions (showing 51 of 579)
| Version | Deps | Published |
|---|---|---|
| 0.43.5 | 16 / 14 | |
| 0.43.4 | 16 / 14 | |
| 0.43.3 | 16 / 17 | |
| 0.43.1 | 16 / 17 | |
| 0.43.0 | 16 / 17 | |
| 0.42.31 | 16 / 13 | |
| 0.42.30 | 16 / 12 | |
| 0.42.29 | 16 / 12 | |
| 0.42.28 | 16 / 12 | |
| 0.42.27 | 16 / 12 | |
| 0.42.26 | 16 / 12 | |
| 0.42.25 | 16 / 12 | |
| 0.42.24 | 16 / 12 | |
| 0.42.23 | 16 / 12 | |
| 0.42.22 | 16 / 11 | |
| 0.42.21 | 16 / 11 | |
| 0.42.20 | 16 / 11 | |
| 0.42.19 | 16 / 11 | |
| 0.42.18 | 16 / 11 | |
| 0.42.17 | 16 / 11 | |
| 0.42.16 | 16 / 11 | |
| 0.42.15 | 16 / 11 | |
| 0.42.14 | 16 / 9 | |
| 0.42.13 | 16 / 6 | |
| 0.42.12 | 16 / 6 | |
| 0.42.11 | 16 / 6 | |
| 0.42.10 | 16 / 6 | |
| 0.42.9 | 16 / 6 | |
| 0.42.8 | 16 / 6 | |
| 0.42.7 | 16 / 6 | |
| 0.42.6 | 16 / 6 | |
| 0.42.5 | 16 / 6 | |
| 0.42.4 | 16 / 6 | |
| 0.42.3 | 16 / 6 | |
| 0.42.2 | 16 / 6 | |
| 0.42.1 | 16 / 6 | |
| 0.42.0 | 16 / 6 | |
| 0.41.13 | 16 / 6 | |
| 0.41.12 | 16 / 6 | |
| 0.41.11 | 16 / 6 | |
| 0.41.10 | 16 / 6 | |
| 0.41.9 | 16 / 6 | |
| 0.41.8 | 16 / 6 | |
| 0.41.7 | 16 / 6 | |
| 0.41.6 | 16 / 6 | |
| 0.41.5 | 16 / 6 | |
| 0.41.4 | 16 / 6 | |
| 0.41.3 | 16 / 6 | |
| 0.41.2 | 16 / 6 | |
| 0.41.1 | 16 / 6 | |
| 0.41.0 | 16 / 6 |
v0.43.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: uifrnbot.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.41.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.41.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.