@frontmcp/ui
FrontMCP UI - MUI-based React components, renderers, and MCP bridge for MCP applications
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped package @frontmcp/ui; not a typosquat of uuid. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package @frontmcp/ui; not a typosquat of pg. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped package @frontmcp/ui; not a typosquat of qs. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @frontmcp/ui; not a typosquat of joi. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped package @frontmcp/ui; not a typosquat of yup. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Used solely to wrap dynamic import() for ESM compatibility in bundled output; not arbitrary code execution. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 1.5.7 | 0 / 6 | |
| 1.5.6 | 0 / 6 | |
| 1.5.5 | 0 / 6 | |
| 1.5.4 | 0 / 6 | |
| 1.5.3 | 0 / 6 | |
| 1.5.2 | 0 / 6 | |
| 1.5.1 | 0 / 6 | |
| 1.5.0 | 0 / 6 | |
| 1.4.1 | 0 / 6 | |
| 1.4.0 | 0 / 6 | |
| 1.3.0 | 0 / 6 | |
| 1.2.1 | 0 / 6 | |
| 1.2.0 | 0 / 6 | |
| 1.1.2 | 0 / 6 | |
| 1.1.1 | 0 / 6 | |
| 1.1.0 | 0 / 6 | |
| 1.0.4 | 0 / 6 | |
| 0.12.2 | 4 / 3 | |
| 0.12.1 | 4 / 3 | |
| 0.12.0 | 4 / 3 | |
| 0.11.3 | 4 / 3 | |
| 0.11.2 | 4 / 3 | |
| 0.11.1 | 4 / 3 | |
| 0.11.0 | 4 / 3 | |
| 0.10.0 | 4 / 3 | |
| 0.9.0 | 4 / 3 | |
| 0.8.1 | 4 / 3 | |
| 0.8.0 | 4 / 3 | |
| 0.7.2 | 4 / 3 | |
| 0.7.1 | 4 / 3 | |
| 0.6.3 | 4 / 3 | |
| 0.6.2 | 4 / 3 | |
| 0.5.1 | 6 / 3 | |
| 0.5.0 | 6 / 3 |
v1.5.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.