@radix-ui/number
13
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
hadihallakchancestricklandmark-workosnpm-workos
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA-attested CI publish; gitHead absence is a benign env change for this official package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher change from benoitgrelard to jjenzz reflects a legitimate maintainer rotation within the Radix UI core team; both are known contributors to radix-ui/primitives. | ai | |
| bogus-package | bogus-package | AI (bogus-package): @radix-ui/number is a legitimate internal utility package in the Radix UI primitives monorepo. Missing description/keywords are consistent across the entire @radix-ui/* namespace. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Absence of description is a consistent pattern across @radix-ui/* utility packages; not an indicator of malicious intent. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): @babel/runtime is a standard build-time dependency used across the Radix UI monorepo; phantom detection is a false positive here. | ai | |
| provenance | no-provenance | AI (provenance): This version predates Sigstore provenance adoption (published 2021); lack of provenance is expected for packages of this age. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 1.1.3 | 0 / 3 | |
| 1.1.2 | 0 / 3 | |
| 1.1.1 | 0 / 4 | |
| 1.1.0 | 0 / 0 | |
| 1.0.1 | 1 / 0 | |
| 1.0.0 | 1 / 0 | |
| 0.1.0 | 1 / 0 | |
| 0.0.6 | 1 / 0 | |
| 0.0.5 | 1 / 0 | |
| 0.0.4 | 1 / 0 | |
| 0.0.3 | 1 / 0 | |
| 0.0.2 | 1 / 0 | |
| 0.0.1 | 0 / 0 |
v1.1.3
2 findings
HIGH
Missing gitHead — previous versions had it
provenance
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.