← Home

@nx/react

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

nrwlownernrwl-jasonjack-nrwlmaxk-nrwljameshenry

Keywords

MonorepoReactWebJestCypressCLIFront-end

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-bulk-read AI (semgrep): Filters only NX_PUBLIC_ and STORYBOOK_ prefixed env vars for Storybook config; standard pattern for this package. ai
semgrep semgrep:child-process-import AI (semgrep): Used in module-federation static server executor; expected build-tool behavior for @nx/react. ai

Versions (showing 51 of 56)

View all versions
Version Deps Published
23.1.0 13 / 8
23.0.2 13 / 8
23.0.1 13 / 8
23.0.0 13 / 8
22.7.7 14 / 8
22.7.6 14 / 8
22.7.5 14 / 8
22.7.4 14 / 8
22.7.3 14 / 8
22.7.2 14 / 8
22.7.1 14 / 8
22.7.0 14 / 8
22.6.5 14 / 8
22.6.4 14 / 8
22.6.3 14 / 8
22.6.2 14 / 8
22.6.1 14 / 8
22.6.0 14 / 8
22.5.4 14 / 8
22.5.3 14 / 8
22.5.2 14 / 8
22.5.1 14 / 8
22.5.0 14 / 8
22.4.5 14 / 8
22.4.4 14 / 8
22.4.3 14 / 8
22.4.2 14 / 8
22.4.1 15 / 8
22.4.0 15 / 8
22.3.3 15 / 7
22.3.2 15 / 7
22.3.1 15 / 7
22.3.0 15 / 7
22.2.7 15 / 7
22.2.6 15 / 7
22.2.5 15 / 7
22.2.4 15 / 7
22.2.3 15 / 7
22.2.2 15 / 7
22.2.1 15 / 7
22.2.0 15 / 7
22.1.3 15 / 7
22.1.2 15 / 7
22.1.1 15 / 7
22.1.0 15 / 7
22.0.4 15 / 6
22.0.3 15 / 6
22.0.2 15 / 6
22.0.1 15 / 6
22.0.0 15 / 6
21.6.11 15 / 6

v23.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v23.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.7.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.