← Home

@nexora-ui/headless

Meta package that installs all @nexora-ui headless libraries.

9
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

zeyadelshafey

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@nexora-ui/core AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/menu AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/select AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/listbox AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/mention AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/overlay AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/popover AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/tooltip AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/combobox AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/dropdown AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/snackbar AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/listbox-cdk AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai
phantom-deps phantom-dep:@nexora-ui/interactions AI (phantom-deps): Meta-package pattern; dependencies are re-exported, not directly imported. ai

Versions (showing 9 of 9)

Version Deps Published
0.2.3 13 / 0
0.2.2 13 / 0
0.2.1 13 / 0
0.2.0 13 / 0
0.1.3 13 / 0
0.1.2 13 / 0
0.1.1 13 / 0
0.1.0 13 / 0
0.0.1 13 / 0

v0.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.