@gitlab/duo-ui
Duo UI Components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:echarts | AI (phantom-deps): echarts is a declared runtime dep used via config; phantom-dep heuristic false positive for this component library. | ai | |
| phantom-deps | phantom-dep:popper.js | AI (phantom-deps): popper.js declared as runtime dep; config-file reference pattern expected for this UI library. | ai | |
| phantom-deps | phantom-dep:portal-vue | AI (phantom-deps): portal-vue declared as runtime dep; config-file reference pattern expected for this UI library. | ai | |
| phantom-deps | phantom-dep:iframe-resizer | AI (phantom-deps): iframe-resizer declared as runtime dep; config-file reference pattern expected for this UI library. | ai | |
| phantom-deps | phantom-dep:vue-functional-data-merge | AI (phantom-deps): vue-functional-data-merge declared as runtime dep; config-file reference pattern expected for this UI library. | ai |
Versions (showing 51 of 89)
| Version | Deps | Published |
|---|---|---|
| 15.34.0 | 13 / 101 | |
| 15.33.0 | 13 / 101 | |
| 15.32.0 | 13 / 101 | |
| 15.31.2 | 13 / 101 | |
| 15.31.1 | 13 / 101 | |
| 15.31.0 | 13 / 101 | |
| 15.30.0 | 13 / 101 | |
| 15.29.0 | 13 / 101 | |
| 15.28.1 | 13 / 101 | |
| 15.28.0 | 13 / 101 | |
| 15.27.1 | 13 / 101 | |
| 15.27.0 | 13 / 101 | |
| 15.26.2 | 13 / 101 | |
| 15.26.1 | 13 / 101 | |
| 15.26.0 | 13 / 101 | |
| 15.25.1 | 13 / 101 | |
| 15.25.0 | 13 / 101 | |
| 15.24.0 | 13 / 101 | |
| 15.23.0 | 13 / 101 | |
| 15.22.0 | 13 / 101 | |
| 15.21.1 | 13 / 101 | |
| 15.21.0 | 13 / 101 | |
| 15.20.0 | 13 / 101 | |
| 15.19.1 | 13 / 101 | |
| 15.19.0 | 13 / 101 | |
| 15.18.0 | 13 / 101 | |
| 15.17.0 | 13 / 101 | |
| 15.16.1 | 13 / 101 | |
| 15.16.0 | 13 / 101 | |
| 15.15.1 | 13 / 101 | |
| 15.15.0 | 13 / 101 | |
| 15.14.0 | 13 / 101 | |
| 15.13.0 | 13 / 100 | |
| 15.12.1 | 13 / 100 | |
| 15.12.0 | 13 / 100 | |
| 15.11.0 | 13 / 100 | |
| 15.10.1 | 13 / 100 | |
| 15.10.0 | 13 / 100 | |
| 15.9.0 | 13 / 100 | |
| 15.8.3 | 13 / 100 | |
| 15.8.2 | 13 / 100 | |
| 15.8.1 | 13 / 100 | |
| 15.8.0 | 13 / 100 | |
| 15.7.2 | 13 / 100 | |
| 15.7.1 | 13 / 100 | |
| 15.7.0 | 13 / 100 | |
| 15.6.0 | 13 / 100 | |
| 15.5.1 | 13 / 100 | |
| 15.5.0 | 13 / 100 | |
| 15.4.2 | 13 / 100 | |
| 15.4.1 | 13 / 100 |
v15.34.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v15.33.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v15.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v15.31.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v15.31.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v15.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v15.30.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.29.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.28.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.28.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.27.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.27.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.26.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.26.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.26.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.25.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.25.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.24.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.23.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.22.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.21.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.21.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.20.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.19.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.19.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.18.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.17.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.16.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.16.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.15.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.15.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.13.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.12.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.10.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.9.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.8.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.8.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.8.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.7.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.7.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.4.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v15.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.