@instructure/ui-toggle-details
A styled toggleable, accordion-like component.
16
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
jakeoedinginstuicisvc.brandablecss-cimaths22jcrystalitadminsaogata-instpkovaacskyler-instructureericsaupexcudderjdewarjozsefg-instructurejacksonhowekaroly.bujtor.instructureevatapaisarahgerardkercsojforbidwolfbencefarkasodmehbvikingpingvinajmal-esarobinkuss64david.wenzlick.instrazorsh4rkardenabpjatacsukangela.gombanatearmstronginstjoyenjoyercguanzon-instherrtopimatyas.szabocjs118camraydmz985christopher.sotokristofkulcsarmhulse_instsvetlintanyimhogensontreybean_instjason.madsenppesti-instadrian.gruberdaniel.kispalinstructure-npm-write-svc-accountaaronshafszilard.doro-instmartongreczi-instinstoutsvcquizzesnpmbalazs.buri.instructuredaniel-torokfmarcsopeipeizhouis-adamszaborajmund-instdanny-instructure
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Monorepo CI publish quirk; no behavioral change, still SLSA-attested. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is a same-org sibling pinned to the same monorepo version; consistent pattern for this package family. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of mstarkman alongside addition of Instructure team members is consistent with a legitimate org transition. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): All new maintainers are Instructure-affiliated accounts; consistent with org team expansion. | ai | |
| provenance | publisher-changed | AI (provenance): Instructure migrated publishing to GitHub Actions CI with SLSA attestation; stable pattern for this org's packages. | ai | |
| dependencies | unvetted-dep:@instructure/ui-testable | AI (dependencies): Same-org monorepo sibling pinned to matching version; consistent with normal Instructure UI releases. | ai | |
| dependencies | unvetted-dep:@instructure/ui-prop-types | AI (dependencies): Same-org monorepo sibling pinned to matching version; consistent with normal Instructure UI releases. | ai | |
| phantom-deps | phantom-dep:@instructure/uid | AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@instructure/ui-utils | AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic is a stable false positive for this package. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 11.7.4 | 14 / 6 | |
| 11.7.3 | 14 / 6 | |
| 11.7.2 | 13 / 7 | |
| 11.7.1 | 13 / 7 | |
| 11.7.0 | 13 / 7 | |
| 11.6.0 | 13 / 7 | |
| 11.5.0 | 13 / 7 | |
| 11.4.0 | 13 / 7 | |
| 11.3.0 | 13 / 7 | |
| 11.2.0 | 13 / 7 | |
| 11.0.1 | 13 / 7 | |
| 11.0.0 | 13 / 7 | |
| 10.30.0 | 16 / 7 | |
| 10.29.0 | 16 / 7 | |
| 10.26.4 | 16 / 7 | |
| 10.26.3 | 16 / 7 |
v11.7.4
2 findings
HIGH
Missing gitHead — previous versions had it
provenance
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.