@fluentui/react-provider
Fluent UI React provider component
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): This is a legitimate Microsoft Fluent UI monorepo component package. Short README and no keywords are typical for monorepo sub-packages, not spam indicators. | ai | |
| provenance | no-provenance | AI (provenance): Microsoft's Fluent UI packages do not currently publish Sigstore provenance; this is consistent across the entire @fluentui/* ecosystem and is not a security concern. | ai | |
| dependencies | unvetted-dep:@griffel/core | AI (dependencies): @griffel/core is the CSS-in-JS engine purpose-built for Fluent UI by Microsoft; it is a legitimate first-party ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@griffel/react | AI (dependencies): @griffel/react is the React binding for Griffel, Microsoft's CSS-in-JS engine for Fluent UI; legitimate first-party dependency. | ai | |
| dependencies | unvetted-dep:@fluentui/react-icons | AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@fluentui/react-theme | AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@fluentui/react-tabster | AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@fluentui/react-utilities | AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@fluentui/react-jsx-runtime | AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@fluentui/react-shared-contexts | AI (dependencies): Sibling @fluentui/* monorepo package from Microsoft; not a third-party risk. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 9.22.17 | 9 / 0 | |
| 9.22.16 | 9 / 0 | |
| 9.22.15 | 9 / 0 | |
| 9.22.14 | 9 / 0 | |
| 9.22.13 | 9 / 0 | |
| 9.22.12 | 9 / 4 | |
| 9.22.11 | 9 / 4 | |
| 9.22.10 | 9 / 4 | |
| 9.22.9 | 9 / 4 | |
| 9.22.8 | 9 / 4 | |
| 9.22.7 | 9 / 4 | |
| 9.22.6 | 9 / 4 | |
| 9.22.5 | 9 / 4 | |
| 9.22.4 | 9 / 4 | |
| 9.22.3 | 9 / 4 | |
| 9.22.2 | 9 / 4 | |
| 9.22.1 | 9 / 4 | |
| 9.22.0 | 9 / 4 | |
| 9.21.3 | 9 / 4 | |
| 9.21.2 | 9 / 4 | |
| 9.21.1 | 9 / 4 | |
| 9.21.0 | 9 / 4 | |
| 9.20.8 | 9 / 4 | |
| 9.20.7 | 9 / 4 |
v9.22.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.22.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.22.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.22.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.21.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.21.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.21.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.20.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.20.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.