@mintlify/components
Mintlify open-source UI components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Change is to GitHub Actions CI publisher, an improvement not a compromise indicator. | ai | |
| phantom-deps | phantom-dep:@base-ui/react | AI (phantom-deps): Used via config/build tooling, not direct import. | ai | |
| phantom-deps | phantom-dep:comlink | AI (phantom-deps): Used via config/build tooling, not direct import. | ai | |
| phantom-deps | phantom-dep:shiki | AI (phantom-deps): Used via config/build tooling, not direct import. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All well-known, established packages consistent with new component features. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Publisher is known long-tenured Mintlify maintainer, provenance unchanged. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Growth from bundled shiki/mermaid/katex language & wasm assets, not injected code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are vendored mermaid/cytoscape/katex bundles; expected for a component library adding diagram/math support. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established Mintlify org package; dormancy reflects scoped package cadence, not account takeover. | ai | |
| dependencies | unvetted-dep:@base-ui-components/react | AI (dependencies): @base-ui-components/react is the official MUI Base UI library; legitimate and well-known dependency. | ai | |
| phantom-deps | phantom-dep:hast | AI (phantom-deps): Bundled component library; deps consumed at build time, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:@sindresorhus/slugify | AI (phantom-deps): Bundled component library; deps consumed at build time, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:@shikijs/transformers | AI (phantom-deps): Bundled component library; deps consumed at build time, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Bundled component library; deps consumed at build time, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:tailwind-merge | AI (phantom-deps): Bundled component library; deps consumed at build time, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:lucide-react | AI (phantom-deps): Bundled component library; deps consumed at build time, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:mermaid | AI (phantom-deps): Bundled component library; deps consumed at build time, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Bundled component library; deps consumed at build time, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:color | AI (phantom-deps): Bundled component library; deps consumed at build time, not directly imported in source. | ai |
Versions (showing 37 of 37)
| Version | Deps | Published |
|---|---|---|
| 1.0.18 | 14 / 29 | |
| 1.0.17 | 14 / 29 | |
| 1.0.16 | 14 / 29 | |
| 1.0.15 | 14 / 29 | |
| 1.0.14 | 14 / 29 | |
| 1.0.13 | 14 / 29 | |
| 1.0.12 | 14 / 29 | |
| 1.0.11 | 14 / 29 | |
| 1.0.10 | 14 / 29 | |
| 1.0.9 | 14 / 29 | |
| 1.0.8 | 14 / 29 | |
| 1.0.7 | 14 / 29 | |
| 1.0.6 | 14 / 29 | |
| 1.0.5 | 14 / 29 | |
| 1.0.4 | 14 / 29 | |
| 1.0.3 | 13 / 29 | |
| 1.0.2 | 13 / 29 | |
| 1.0.1 | 13 / 29 | |
| 1.0.0 | 13 / 28 | |
| 0.4.17 | 3 / 24 | |
| 0.4.16 | 3 / 24 | |
| 0.4.15 | 3 / 24 | |
| 0.4.14 | 3 / 24 | |
| 0.4.13 | 3 / 24 | |
| 0.4.12 | 3 / 24 | |
| 0.4.11 | 3 / 24 | |
| 0.4.10 | 3 / 24 | |
| 0.4.9 | 3 / 24 | |
| 0.4.8 | 3 / 24 | |
| 0.4.7 | 2 / 24 | |
| 0.4.6 | 2 / 24 | |
| 0.4.5 | 1 / 23 | |
| 0.4.4 | 1 / 23 | |
| 0.4.3 | 1 / 23 | |
| 0.4.2 | 1 / 23 | |
| 0.4.1 | 1 / 23 | |
| 0.4.0 | 1 / 23 |
v1.0.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.16
2 findingsThis version was published by a different npm account than previous versions on 2026-04-17. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.15
2 findingsThis version was published by a different npm account than previous versions on 2026-04-08. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.14
2 findingsThis version was published by a different npm account than previous versions on 2026-03-21. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.13
2 findingsThis version was published by a different npm account than previous versions on 2026-03-19. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.12
2 findingsThis version was published by a different npm account than previous versions on 2026-03-18. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.11
2 findingsThis version was published by a different npm account than previous versions on 2026-03-13. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.10
2 findingsThis version was published by a different npm account than previous versions on 2026-03-11. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.9
2 findingsThis version was published by a different npm account than previous versions on 2026-03-11. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.8
2 findingsThis version was published by a different npm account than previous versions on 2026-03-10. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.7
2 findingsThis version was published by a different npm account than previous versions on 2026-03-09. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.6
2 findingsThis version was published by a different npm account than previous versions on 2026-03-06. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.5
2 findingsThis version was published by a different npm account than previous versions on 2026-02-12. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.4
2 findingsThis version was published by a different npm account than previous versions on 2026-02-09. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.3
2 findingsThis version was published by a different npm account than previous versions on 2026-02-06. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kathrynmintlify) than the most recent previously approved version (dks333) on 2026-01-31, but kathrynmintlify is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kathrynmintlify) than the most recent previously approved version (dks333) on 2026-01-26, but kathrynmintlify is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kathrynmintlify) than the most recent previously approved version (dks333) on 2026-01-24, but kathrynmintlify is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.