@notion-kit/settings-panel
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Monorepo component package; missing description is a stable pattern across all @notion-kit/* packages. | ai | |
| provenance | no-provenance | AI (provenance): No provenance across all versions; consistent with this publisher's release workflow. | ai | |
| phantom-deps | phantom-dep:@notion-kit/icons | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@hookform/resolvers | AI (phantom-deps): Monorepo bundle pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@notion-kit/icon-menu | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): Monorepo bundle pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@notion-kit/tags-input | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@stripe/react-stripe-js | AI (phantom-deps): Monorepo bundle pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:file-saver | AI (phantom-deps): Monorepo bundle pattern; deps declared at package level but consumed via bundled dist. | ai | |
| phantom-deps | phantom-dep:usehooks-ts | AI (phantom-deps): Monorepo bundle pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@notion-kit/cn | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Monorepo bundle pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@notion-kit/hooks | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@notion-kit/utils | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@notion-kit/common | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@notion-kit/shadcn | AI (phantom-deps): Same-org monorepo dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@date-fns/tz | AI (phantom-deps): Used in build/config context for timezone support; not a direct import but legitimately declared. | ai | |
| dependencies | unvetted-dep:@notion-kit/spinner | AI (dependencies): Sibling package in the same @notion-kit monorepo; publisher has 119 approved packages. | ai | |
| dependencies | unvetted-dep:@notion-kit/select | AI (dependencies): Sibling package in the same @notion-kit monorepo; publisher has 119 approved packages. | ai | |
| dependencies | unvetted-dep:@notion-kit/modal | AI (dependencies): Sibling package in the same @notion-kit monorepo; publisher has 119 approved packages. | ai | |
| dependencies | unvetted-dep:@notion-kit/i18n | AI (dependencies): Sibling package in the same @notion-kit monorepo; publisher has 119 approved packages. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 0.16.0 | 20 / 11 | |
| 0.15.1 | 19 / 11 | |
| 0.15.0 | 19 / 11 | |
| 0.10.0 | 19 / 10 | |
| 0.8.1 | 18 / 10 | |
| 0.8.0 | 18 / 10 | |
| 0.7.0 | 16 / 10 | |
| 0.6.1 | 16 / 10 | |
| 0.5.0 | 17 / 10 | |
| 0.4.0 | 17 / 10 |
v0.16.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.15.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.15.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.