← Home

@pisell/date-picker

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

wang_hanzsj1037797769zhiwei.wangyaoxiaojialarry_ranhejunxiangfeng.xueah-scjinglin.tan

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): Actively developed UI component library; new source files reflect feature additions, not injected code. ai
maintainer-change maintainer-removed AI (maintainer-change): Active multi-maintainer package; maintainer rotation is expected across 161 versions. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers yaoxiaojia and larry_ranhejun added alongside known publisher jinglin.tan; consistent with team expansion, not takeover. ai
bogus-package bogus-package AI (bogus-package): @pisell/date-picker is an established internal component library with 159 versions; missing README/repo metadata is a quality issue, not a security concern. ai
dependencies unvetted-dep:@mui/base AI (dependencies): @mui/base is a well-known MUI library; beta version is expected for a date-picker component built on MUI ecosystem. Stable false positive for this package. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom is declared as a runtime dep for UI component library consumers; not directly imported in source is expected for this type of package. ai
phantom-deps phantom-dep:@emotion/styled AI (phantom-deps): MUI-based component libraries commonly declare @emotion/styled as a dependency without directly importing it in every source file. ai
phantom-deps phantom-dep:@emotion/react AI (phantom-deps): MUI-based component libraries commonly declare @emotion/react as a dependency without directly importing it in every source file. ai

Versions (showing 51 of 148)

View all versions
Version Deps Published
3.0.10 14 / 2
3.0.9 14 / 2
3.0.8 14 / 2
1.0.145 14 / 6
1.0.144 14 / 6
1.0.143 14 / 6
1.0.141 14 / 6
1.0.140 14 / 6
1.0.139 14 / 6
1.0.138 14 / 6
1.0.137 14 / 6
1.0.136 14 / 6
1.0.135 14 / 6
1.0.134 14 / 6
1.0.133 14 / 6
1.0.132 14 / 6
1.0.131 14 / 6
1.0.130 14 / 6
1.0.129 14 / 6
1.0.128 14 / 6
1.0.127 14 / 2
1.0.126 14 / 2
1.0.125 14 / 2
1.0.124 14 / 2
1.0.123 14 / 2
1.0.122 14 / 2
1.0.121 14 / 2
1.0.120 14 / 2
1.0.119 14 / 2
1.0.118 14 / 2
1.0.117 14 / 2
1.0.116 14 / 2
1.0.115 14 / 2
1.0.114 14 / 2
1.0.113 14 / 2
1.0.112 14 / 2
1.0.111 14 / 2
1.0.110 14 / 2
1.0.109 14 / 2
1.0.108 14 / 2
1.0.107 14 / 2
1.0.106 14 / 2
1.0.105 14 / 2
1.0.104 14 / 2
1.0.103 14 / 2
1.0.102 14 / 2
1.0.101 14 / 2
1.0.100 14 / 2
1.0.99 14 / 2
1.0.98 14 / 2
1.0.97 14 / 2

v3.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.145

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.141

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.140

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.139

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.138

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.137

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.136

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.135

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.134

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.133

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.132

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ah-sc → yaoxiaojia (on 2026-02-05, known maintainer) provenance

This version was published by a different npm account (yaoxiaojia) than the most recent previously approved version (ah-sc) on 2026-02-05, but yaoxiaojia is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.131

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ah-sc → yaoxiaojia (on 2026-02-02, known maintainer) provenance

This version was published by a different npm account (yaoxiaojia) than the most recent previously approved version (ah-sc) on 2026-02-02, but yaoxiaojia is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.129

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → zhiwei.wang (on 2026-01-23, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (zsj1037797769) on 2026-01-23, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.126

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: xiangfeng.xue → zsj1037797769 (on 2025-09-02, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (xiangfeng.xue) on 2025-09-02, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.125

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: xiangfeng.xue → jinglin.tan (on 2025-09-01, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (xiangfeng.xue) on 2025-09-01, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.123

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.122

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.121

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.119

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.115

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.114

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zhiwei.wang → zsj1037797769 (on 2025-01-04, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (zhiwei.wang) on 2025-01-04, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.113

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zhiwei.wang → wang_han (on 2024-12-15, known maintainer) provenance

This version was published by a different npm account (wang_han) than the most recent previously approved version (zhiwei.wang) on 2024-12-15, but wang_han is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.112

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → zhiwei.wang (on 2024-11-20, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (zsj1037797769) on 2024-11-20, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.111

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.110

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zhiwei.wang → zsj1037797769 (on 2024-09-12, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (zhiwei.wang) on 2024-09-12, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.109

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.108

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.107

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.106

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → zhiwei.wang (on 2024-09-05, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (zsj1037797769) on 2024-09-05, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.105

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.104

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.103

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zsj1037797769 → zhiwei.wang (on 2024-09-02, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (zsj1037797769) on 2024-09-02, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.102

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.101

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.100

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.99

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.98

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.97

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.