← Home

@mui/x-telemetry

5
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cherniavskiilukastylaalexandrefauquettedanailhflaviendelangleoliviertassinarimbilalshafijcquintaskyusufmichelengelennoraleontearminmehromgrkbernardobelchiorrita-codesjanpotoms

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:postinstall AI (install-scripts): Official MUI X telemetry package; postinstall initializes anonymous project ID hashing, documented behavior. ai
semgrep semgrep:child-process-import AI (semgrep): child_process used in postinstall for project path hashing (anonymous telemetry ID); consistent with package purpose. ai

Versions (showing 5 of 5)

Version Deps Published
9.2.0 5 / 0
9.1.0 5 / 0
9.0.2 5 / 0
9.0.0 5 / 0
8.16.0 6 / 0

v9.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.0.2

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node ./postinstall/index.mjs

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.