@nayhoo/ui
A collection of React components, built with [Radix Primitives](https://www.radix-ui.com/primitives), styled with [vanilla-extract](https://vanilla-extract.style).
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@radix-ui/react-avatar | AI (dependencies): @radix-ui/react-avatar is a well-known Radix UI primitive; unvetted flag is a false positive for this package. | ai | |
| dependencies | unvetted-dep:@vanilla-extract/esbuild-plugin | AI (dependencies): @vanilla-extract/esbuild-plugin is a well-known build tool; unvetted flag is a false positive for this package. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped UI library; name collision with uuid is coincidental, not impersonation. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped UI library; name collision with pg is coincidental, not impersonation. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped UI library; name collision with qs is coincidental, not impersonation. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped UI library; name collision with joi is coincidental, not impersonation. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped UI library; name collision with yup is coincidental, not impersonation. | ai | |
| phantom-deps | phantom-dep:tsup | AI (phantom-deps): tsup is a build tool referenced in config/scripts; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:@radix-ui/colors | AI (phantom-deps): Design token package used in config/theme files, not direct JS imports. | ai | |
| phantom-deps | phantom-dep:@vanilla-extract/css | AI (phantom-deps): Build-time CSS-in-JS tool; referenced in config, not runtime imports. | ai | |
| phantom-deps | phantom-dep:@vanilla-extract/esbuild-plugin | AI (phantom-deps): Build plugin; used in build config, not runtime imports. | ai |
v0.20.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.19.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.19.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.