← Home

@fluentui/react-provider

Fluent UI React provider component

24
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

chrisdholtmiroslavstastnylevithomasonuifabricteamuifrnbotlayershifterjustslonemicrosoft1essopranopillow

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): This is a legitimate Microsoft Fluent UI monorepo component package. Short README and no keywords are typical for monorepo sub-packages, not spam indicators. ai
provenance no-provenance AI (provenance): Microsoft's Fluent UI packages do not currently publish Sigstore provenance; this is consistent across the entire @fluentui/* ecosystem and is not a security concern. ai
dependencies unvetted-dep:@griffel/core AI (dependencies): @griffel/core is the CSS-in-JS engine purpose-built for Fluent UI by Microsoft; it is a legitimate first-party ecosystem dependency. ai
dependencies unvetted-dep:@griffel/react AI (dependencies): @griffel/react is the React binding for Griffel, Microsoft's CSS-in-JS engine for Fluent UI; legitimate first-party dependency. ai
dependencies unvetted-dep:@fluentui/react-icons AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. ai
dependencies unvetted-dep:@fluentui/react-theme AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. ai
dependencies unvetted-dep:@fluentui/react-tabster AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. ai
dependencies unvetted-dep:@fluentui/react-utilities AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. ai
dependencies unvetted-dep:@fluentui/react-jsx-runtime AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. ai
dependencies unvetted-dep:@fluentui/react-shared-contexts AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. ai

Versions (showing 24 of 24)

Version Deps Published
9.22.17 9 / 0
9.22.16 9 / 0
9.22.15 9 / 0
9.22.14 9 / 0
9.22.13 9 / 0
9.22.12 9 / 4
9.22.11 9 / 4
9.22.10 9 / 4
9.22.9 9 / 4
9.22.8 9 / 4
9.22.7 9 / 4
9.22.6 9 / 4
9.22.5 9 / 4
9.22.4 9 / 4
9.22.3 9 / 4
9.22.2 9 / 4
9.22.1 9 / 4
9.22.0 9 / 4
9.21.3 9 / 4
9.21.2 9 / 4
9.21.1 9 / 4
9.21.0 9 / 4
9.20.8 9 / 4
9.20.7 9 / 4

v9.22.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.22.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.22.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.21.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.21.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.21.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.21.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.20.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.20.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.