← Home

@mui/x-data-grid-premium

47
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cherniavskiilukastylaalexandrefauquettedanailhflaviendelangleoliviertassinarimbilalshafijcquintaskyusufmichelengelennoraleontearminmehromgrkbernardobelchiorrita-codesjanpotoms

Keywords

reactreact-componentmaterial-uimuimui-xreact-tabletabledatatabledata-tabledatagriddata-grid

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): exceljs/reselect replace removed internal exceljs fork; established deps. ai
source-diff net-exec-file:DataGridPremium/DataGridPremium.mjs AI (source-diff): Standard React component code; false positive on MUI's license verifier + JSX runtime imports. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): MUI packages commonly reference clsx in config/type files without direct imports; stable false positive. ai
phantom-deps phantom-dep:reselect AI (phantom-deps): MUI data-grid uses reselect via peer/framework convention; stable false positive. ai
phantom-deps phantom-dep:@types/format-util AI (phantom-deps): Type-only package loaded by convention; phantom-dep heuristic not applicable here. ai
dependencies unvetted-dep:@mui/x-internal-exceljs-fork AI (dependencies): MUI-maintained internal fork of exceljs for Excel export; stable dependency for this package. ai
dependencies unvetted-dep:@mui/x-data-grid-pro AI (dependencies): Sibling MUI X monorepo package; expected dependency for this commercial component. ai
license uncommon-license:SEE LICENSE IN LICENSE AI (license): Standard MUI commercial license format used across all MUI X premium packages. ai
dependencies unvetted-dep:@mui/x-license AI (dependencies): Sibling MUI X monorepo package; expected dependency for this commercial component. ai

Versions (showing 47 of 47)

Version Deps Published
9.10.1 10 / 0
9.10.0 10 / 0
9.9.0 10 / 0
9.8.0 10 / 0
9.7.0 10 / 0
9.6.0 9 / 0
9.5.0 9 / 0
9.4.0 9 / 0
9.3.0 9 / 0
9.2.0 9 / 0
9.1.0 9 / 0
9.0.4 9 / 0
9.0.3 9 / 0
9.0.2 9 / 0
9.0.1 9 / 0
9.0.0 9 / 0
8.29.2 9 / 0
8.29.1 9 / 0
8.29.0 9 / 0
8.28.7 9 / 0
8.28.6 9 / 0
8.28.5 9 / 0
8.28.3 9 / 0
8.28.2 9 / 0
8.28.1 9 / 0
8.28.0 9 / 0
8.27.5 9 / 0
8.27.4 9 / 0
8.27.3 9 / 0
8.27.2 9 / 0
8.27.1 9 / 0
8.27.0 9 / 0
8.26.1 9 / 0
8.26.0 9 / 0
8.25.0 9 / 0
8.24.0 9 / 0
8.23.0 9 / 0
8.22.1 9 / 0
8.22.0 9 / 0
8.21.0 9 / 0
8.20.0 9 / 0
8.19.0 9 / 0
8.18.0 9 / 0
8.17.0 9 / 0
8.16.0 9 / 0
7.29.13 11 / 0
7.29.11 11 / 0

v9.10.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.29.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.29.13

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.

INFO Publisher changed: GitHub Actions → michelengelen (on 2026-04-28, known maintainer) provenance

This version was published by a different npm account (michelengelen) than the most recent previously approved version (GitHub Actions) on 2026-04-28, but michelengelen is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.