← Home

@fuf-stack/megapixels

fuf react advanced components library

76
Versions
MIT
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

toxsickschrob3000janine_fuf

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Moved from personal account to GitHub Actions CI/CD; SLSA provenance confirms legitimate transition. ai
bogus-package bogus-package AI (bogus-package): Monorepo component library; sparse README and no keywords are expected for internal ecosystem packages. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Monorepo with 57 versions; 0.0.0 is a placeholder publish pattern, not a malware indicator. ai
phantom-deps phantom-dep:@fuf-stack/uniform AI (phantom-deps): Monorepo internal dependency; heuristic false positive. ai
phantom-deps phantom-dep:react-icons AI (phantom-deps): Declared dependency used in component library; heuristic false positive. ai
phantom-deps phantom-dep:@fuf-stack/pixel-utils AI (phantom-deps): Monorepo internal dependency; heuristic false positive. ai
phantom-deps phantom-dep:@fuf-stack/veto AI (phantom-deps): Monorepo internal dependency; heuristic false positive. ai
phantom-deps phantom-dep:@fuf-stack/pixels AI (phantom-deps): Monorepo internal dependency; heuristic false positive. ai

Versions (showing 76 of 76)

Version Deps Published
0.15.0 10 / 5
0.14.4 10 / 5
0.14.3 10 / 5
0.14.2 10 / 5
0.14.1 10 / 5
0.14.0 10 / 5
0.13.5 7 / 5
0.13.4 7 / 5
0.13.3 7 / 5
0.13.2 7 / 5
0.12.0 7 / 5
0.11.36 7 / 5
0.11.35 7 / 5
0.11.34 7 / 5
0.11.33 7 / 5
0.11.32 7 / 5
0.11.31 7 / 5
0.11.30 7 / 5
0.11.29 7 / 5
0.11.28 7 / 5
0.11.27 7 / 5
0.11.26 7 / 5
0.11.25 7 / 5
0.11.24 7 / 5
0.11.23 7 / 5
0.11.22 7 / 5
0.11.21 7 / 5
0.11.20 7 / 5
0.11.19 7 / 5
0.11.18 7 / 5
0.11.17 7 / 5
0.11.16 7 / 5
0.11.15 7 / 5
0.11.14 7 / 5
0.11.13 7 / 5
0.11.12 7 / 5
0.11.11 7 / 5
0.11.10 7 / 5
0.11.9 7 / 5
0.11.8 7 / 5
0.11.7 7 / 5
0.11.6 7 / 5
0.11.5 7 / 5
0.11.4 7 / 5
0.11.3 7 / 5
0.11.2 7 / 5
0.11.0 7 / 5
0.10.5 7 / 5
0.10.3 7 / 5
0.10.2 7 / 5
0.10.1 7 / 5
0.9.13 7 / 5
0.9.10 7 / 5
0.9.9 7 / 5
0.9.8 7 / 5
0.9.1 7 / 5
0.9.0 7 / 5
0.7.3 7 / 5
0.7.2 7 / 5
0.7.1 7 / 5
0.6.0 7 / 5
0.5.0 7 / 5
0.4.1 7 / 5
0.4.0 7 / 5
0.3.5 7 / 5
0.3.4 7 / 5
0.3.3 7 / 5
0.3.2 7 / 5
0.3.1 6 / 5
0.3.0 6 / 5
0.2.2 6 / 5
0.2.1 6 / 5
0.2.0 6 / 5
0.1.0 6 / 5
0.0.1 5 / 5
0.0.0 5 / 5

v0.15.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.