@mui/styles
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Manual publish by known MUI maintainer; benign for this package. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 6.5.0 | 17 / 0 | |
| 6.4.12 | 17 / 0 | |
| 6.4.11 | 17 / 0 | |
| 6.4.10 | 17 / 0 | |
| 6.4.9 | 17 / 0 | |
| 6.4.8 | 17 / 0 | |
| 6.4.7 | 17 / 0 | |
| 6.4.6 | 17 / 0 | |
| 6.4.5 | 17 / 0 | |
| 6.4.4 | 17 / 0 | |
| 6.4.3 | 17 / 0 | |
| 6.4.2 | 17 / 0 | |
| 6.4.1 | 17 / 0 | |
| 6.4.0 | 17 / 0 | |
| 6.3.1 | 17 / 0 | |
| 6.3.0 | 17 / 0 | |
| 6.2.1 | 17 / 0 | |
| 6.2.0 | 17 / 0 | |
| 6.1.10 | 17 / 0 | |
| 6.1.9 | 17 / 0 | |
| 6.1.8 | 17 / 0 | |
| 6.1.7 | 17 / 0 | |
| 6.1.6 | 17 / 0 | |
| 6.1.5 | 17 / 0 | |
| 6.1.4 | 17 / 0 | |
| 6.1.3 | 17 / 0 | |
| 6.1.2 | 17 / 0 | |
| 6.1.1 | 17 / 0 | |
| 6.1.0 | 17 / 0 | |
| 6.0.2 | 17 / 0 | |
| 6.0.1 | 17 / 0 | |
| 6.0.0 | 17 / 0 |
v6.5.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: siriwatknp.
v6.4.12
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: siriwatknp.
v6.4.11
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: mj12albert.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mj12albert) than the most recent previously approved version (diegoandai) on 2025-04-09, but mj12albert is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.10
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: aarongarciah.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (aarongarciah) than the most recent previously approved version (diegoandai) on 2025-03-31, but aarongarciah is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.9
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: siriwatknp.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (siriwatknp) than the most recent previously approved version (diegoandai) on 2025-03-25, but siriwatknp is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (brijeshb42) than the most recent previously approved version (aarongarciah) on 2025-03-05, but brijeshb42 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mj12albert) than the most recent previously approved version (aarongarciah) on 2025-02-26, but mj12albert is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (aarongarciah) than the most recent previously approved version (mnajdova) on 2025-02-18, but aarongarciah is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mnajdova) than the most recent previously approved version (diegoandai) on 2025-02-11, but mnajdova is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (diegoandai) than the most recent previously approved version (siriwatknp) on 2025-01-29, but diegoandai is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mnajdova) than the most recent previously approved version (siriwatknp) on 2025-01-21, but mnajdova is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.4.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (siriwatknp) than the most recent previously approved version (mnajdova) on 2025-01-14, but siriwatknp is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.3.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (diegoandai) than the most recent previously approved version (mnajdova) on 2025-01-03, but diegoandai is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.3.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mnajdova) than the most recent previously approved version (mj12albert) on 2024-12-23, but mnajdova is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.2.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (diegoandai) than the most recent previously approved version (mj12albert) on 2024-12-17, but diegoandai is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.2.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mj12albert) than the most recent previously approved version (siriwatknp) on 2024-12-11, but mj12albert is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.10
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (aarongarciah) than the most recent previously approved version (siriwatknp) on 2024-12-04, but aarongarciah is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.9
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (siriwatknp) than the most recent previously approved version (diegoandai) on 2024-11-27, but siriwatknp is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mnajdova) than the most recent previously approved version (diegoandai) on 2024-11-20, but mnajdova is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (diegoandai) than the most recent previously approved version (siriwatknp) on 2024-11-13, but diegoandai is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (aarongarciah) than the most recent previously approved version (siriwatknp) on 2024-10-30, but aarongarciah is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (siriwatknp) than the most recent previously approved version (mnajdova) on 2024-10-22, but siriwatknp is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (diegoandai) than the most recent previously approved version (mnajdova) on 2024-10-15, but diegoandai is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mnajdova) than the most recent previously approved version (siriwatknp) on 2024-10-09, but mnajdova is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (aarongarciah) than the most recent previously approved version (siriwatknp) on 2024-10-02, but aarongarciah is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (siriwatknp) than the most recent previously approved version (brijeshb42) on 2024-09-19, but siriwatknp is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.1.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (diegoandai) than the most recent previously approved version (brijeshb42) on 2024-09-11, but diegoandai is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.0.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (brijeshb42) than the most recent previously approved version (siriwatknp) on 2024-09-03, but brijeshb42 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.0.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (diegoandai) than the most recent previously approved version (siriwatknp) on 2024-08-29, but diegoandai is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.