@material-table/core
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:cors | AI (typosquat): False positive: '@material-table/core' is a well-established React datatable library. The 'core' suffix matching 'cors' is coincidental and unrelated to the cors package. | ai | |
| phantom-deps | phantom-dep:@emotion/core | AI (phantom-deps): @emotion/core is a standard MUI/emotion styling dependency declared for compatibility; phantom detection is a false positive for UI component libraries. | ai | |
| phantom-deps | phantom-dep:@emotion/react | AI (phantom-deps): @emotion/react is a standard MUI styling peer dependency; phantom detection is a false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): @emotion/styled is a standard MUI styling peer dependency; phantom detection is a false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:@date-io/core | AI (phantom-deps): @date-io/core is a standard date adapter used with MUI date pickers; phantom detection is a false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:classnames | AI (phantom-deps): classnames is a common utility used in UI libraries; phantom detection is a false positive here. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 8.0.3 | 13 / 16 | |
| 8.0.2 | 13 / 16 | |
| 8.0.1 | 13 / 16 | |
| 8.0.0 | 13 / 16 | |
| 7.0.0 | 17 / 45 |
v8.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.0
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version was published by a different npm account (dominoengel) than the most recent previously approved version (GitHub Actions) on 2026-07-19, but dominoengel is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.