@jtl-software/platform-ui-react
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@radix-ui/react-avatar | AI (dependencies): Part of the Radix UI ecosystem used throughout this package; consistent with its UI component library purpose. | ai | |
| phantom-deps | phantom-dep:react-use | AI (phantom-deps): Declared runtime dep in a UI library; likely re-exported or used in build config, not a phantom. | ai | |
| phantom-deps | phantom-dep:react-imask | AI (phantom-deps): Declared runtime dep; consistent with form input masking features in this UI library. | ai | |
| phantom-deps | phantom-dep:@tiptap/extensions | AI (phantom-deps): Declared runtime dep; consistent with rich text editor features using TipTap. | ai | |
| phantom-deps | phantom-dep:@hookform/resolvers | AI (phantom-deps): Declared runtime dep; consistent with form validation features in this UI library. | ai | |
| phantom-deps | phantom-dep:tailwindcss-animate | AI (phantom-deps): Declared runtime dep; used as a Tailwind plugin in config, not directly imported in JS. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-separator | AI (phantom-deps): Part of Radix UI ecosystem; declared runtime dep consistent with this UI component library. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 1.51.2 | 56 / 58 | |
| 1.51.1 | 56 / 58 | |
| 1.51.0 | 56 / 58 | |
| 1.43.1 | 44 / 57 |
v1.51.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.51.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.51.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.