@jtl-software/platform-ui-react
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@radix-ui/react-avatar | AI (dependencies): Part of the Radix UI ecosystem used throughout this package; consistent with its UI component library purpose. | ai | |
| phantom-deps | phantom-dep:react-use | AI (phantom-deps): Declared runtime dep in a UI library; likely re-exported or used in build config, not a phantom. | ai | |
| phantom-deps | phantom-dep:react-imask | AI (phantom-deps): Declared runtime dep; consistent with form input masking features in this UI library. | ai | |
| phantom-deps | phantom-dep:@tiptap/extensions | AI (phantom-deps): Declared runtime dep; consistent with rich text editor features using TipTap. | ai | |
| phantom-deps | phantom-dep:@hookform/resolvers | AI (phantom-deps): Declared runtime dep; consistent with form validation features in this UI library. | ai | |
| phantom-deps | phantom-dep:tailwindcss-animate | AI (phantom-deps): Declared runtime dep; used as a Tailwind plugin in config, not directly imported in JS. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-separator | AI (phantom-deps): Part of Radix UI ecosystem; declared runtime dep consistent with this UI component library. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 1.56.1 | 56 / 59 | |
| 1.56.0 | 56 / 59 | |
| 1.55.1 | 56 / 59 | |
| 1.55.0 | 56 / 59 | |
| 1.54.2 | 56 / 59 | |
| 1.54.1 | 56 / 59 | |
| 1.54.0 | 56 / 59 | |
| 1.53.0 | 56 / 59 | |
| 1.52.2 | 56 / 59 | |
| 1.52.1 | 56 / 58 | |
| 1.52.0 | 56 / 58 | |
| 1.51.2 | 56 / 58 | |
| 1.51.1 | 56 / 58 | |
| 1.51.0 | 56 / 58 | |
| 1.50.0 | 56 / 58 | |
| 1.49.0 | 56 / 58 | |
| 1.48.0 | 54 / 58 | |
| 1.47.0 | 54 / 58 | |
| 1.46.0 | 54 / 58 | |
| 1.45.1 | 54 / 58 | |
| 1.45.0 | 54 / 58 | |
| 1.44.1 | 54 / 58 | |
| 1.44.0 | 54 / 58 | |
| 1.43.1 | 44 / 57 | |
| 1.43.0 | 44 / 57 | |
| 1.42.3 | 44 / 57 | |
| 1.41.0 | 43 / 55 | |
| 1.40.1 | 43 / 55 | |
| 1.40.0 | 43 / 55 |
v1.56.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.56.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.55.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.55.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.54.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.54.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.54.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.50.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.49.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.48.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.45.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.45.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.44.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.44.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.43.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.