@heroui/use-aria-accordion
React-aria useAccordion hooks with custom implementations
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): HeroUI monorepo publishes in batches; dormancy reflects release cadence, not takeover risk given consistent publisher track record. | ai | |
| provenance | no-provenance | AI (provenance): Established publisher with 47 approved packages; lack of provenance is consistent across all versions. | ai | |
| dependencies | unvetted-dep:@react-types/accordion | AI (dependencies): Known React Aria types package; alpha versioning is expected for this package and stable for HeroUI's use. | ai | |
| phantom-deps | phantom-dep:@react-aria/utils | AI (phantom-deps): @react-aria/utils is a declared runtime dep used transitively; phantom-dep false positive for this package. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 2.2.20 | 6 / 0 | |
| 2.2.19 | 6 / 0 | |
| 2.2.17 | 6 / 0 | |
| 2.2.16 | 6 / 0 | |
| 2.2.15 | 6 / 0 | |
| 2.2.13 | 6 / 0 | |
| 2.2.12 | 7 / 0 | |
| 2.2.10 | 7 / 0 | |
| 2.2.9 | 7 / 0 | |
| 2.2.8 | 7 / 0 | |
| 2.2.7 | 7 / 0 | |
| 2.2.6 | 7 / 0 | |
| 2.2.4 | 7 / 0 | |
| 2.2.3 | 7 / 0 | |
| 2.2.2 | 7 / 0 |
v2.2.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.