← Home

@material-table/core

5
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

oze4lukss12dominoengel

Keywords

reactmaterial-uimaterialmuidatatabletable

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:cors AI (typosquat): False positive: '@material-table/core' is a well-established React datatable library. The 'core' suffix matching 'cors' is coincidental and unrelated to the cors package. ai
phantom-deps phantom-dep:@emotion/core AI (phantom-deps): @emotion/core is a standard MUI/emotion styling dependency declared for compatibility; phantom detection is a false positive for UI component libraries. ai
phantom-deps phantom-dep:@emotion/react AI (phantom-deps): @emotion/react is a standard MUI styling peer dependency; phantom detection is a false positive for this UI library. ai
phantom-deps phantom-dep:@emotion/styled AI (phantom-deps): @emotion/styled is a standard MUI styling peer dependency; phantom detection is a false positive for this UI library. ai
phantom-deps phantom-dep:@date-io/core AI (phantom-deps): @date-io/core is a standard date adapter used with MUI date pickers; phantom detection is a false positive for this UI library. ai
phantom-deps phantom-dep:classnames AI (phantom-deps): classnames is a common utility used in UI libraries; phantom detection is a false positive here. ai

Versions (showing 5 of 5)

Version Deps Published
8.0.3 13 / 16
8.0.2 13 / 16
8.0.1 13 / 16
8.0.0 13 / 16
7.0.0 17 / 45

v8.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.0.0

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.

INFO Publisher changed: GitHub Actions → dominoengel (on 2026-07-19, known maintainer) provenance

This version was published by a different npm account (dominoengel) than the most recent previously approved version (GitHub Actions) on 2026-07-19, but dominoengel is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.