@launchpad-ui/core
Contains all LaunchPad design system packages.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@launchpad-ui/form | AI (phantom-deps): Umbrella re-export package; all @launchpad-ui/* deps are re-exported, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/navigation | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/focus-trap | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/dropdown | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/tooltip | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/popover | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/overlay | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/portal | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/filter | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/drawer | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/button | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/table | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/modal | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@launchpad-ui/menu | AI (phantom-deps): Same umbrella re-export pattern; stable false positive. | ai | |
| provenance | publisher-changed | AI (provenance): LaunchDarkly migrated publishing to GitHub Actions CI/CD; confirmed by SLSA Sigstore attestation on every release. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Legitimate LaunchDarkly design system package; name similarity to 'cors' is coincidental substring match, not a squatting attempt. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/navigation | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/focus-trap | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/dropdown | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/tooltip | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/popover | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/overlay | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/portal | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/filter | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/drawer | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/button | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/table | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/modal | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/menu | AI (dependencies): Sibling package in the same LaunchDarkly monorepo. | ai | |
| dependencies | unvetted-dep:@launchpad-ui/form | AI (dependencies): Sibling package in the same LaunchDarkly monorepo; not an external unvetted dependency. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 0.59.17 | 14 / 2 | |
| 0.59.16 | 14 / 2 | |
| 0.59.15 | 14 / 2 | |
| 0.59.14 | 14 / 2 | |
| 0.59.13 | 14 / 2 | |
| 0.59.12 | 14 / 2 | |
| 0.59.11 | 14 / 2 | |
| 0.59.10 | 14 / 2 | |
| 0.59.9 | 14 / 2 | |
| 0.59.8 | 14 / 2 | |
| 0.59.7 | 14 / 2 | |
| 0.59.6 | 14 / 2 | |
| 0.59.5 | 14 / 2 | |
| 0.59.4 | 14 / 2 | |
| 0.59.3 | 14 / 2 | |
| 0.59.2 | 14 / 2 | |
| 0.59.1 | 14 / 2 | |
| 0.59.0 | 14 / 2 | |
| 0.58.0 | 14 / 2 | |
| 0.57.0 | 14 / 2 | |
| 0.56.14 | 14 / 2 | |
| 0.56.13 | 14 / 2 | |
| 0.56.12 | 14 / 2 | |
| 0.56.11 | 14 / 2 | |
| 0.56.10 | 14 / 2 | |
| 0.56.9 | 14 / 2 | |
| 0.56.8 | 14 / 2 | |
| 0.56.7 | 14 / 2 | |
| 0.56.6 | 14 / 2 | |
| 0.56.5 | 14 / 2 | |
| 0.56.4 | 14 / 2 | |
| 0.56.3 | 14 / 2 |
v0.59.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.16
2 findingsPackage name '@launchpad-ui/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.15
2 findingsThis version was published by a different npm account than previous versions on 2026-04-07. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.14
2 findingsThis version was published by a different npm account than previous versions on 2026-04-07. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.58.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.4
2 findingsPackage name '@launchpad-ui/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.3
2 findingsPackage name '@launchpad-ui/core' is 1 edit(s) away from popular package 'cors'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.