← Home

@radix-ui/react-collapsible

View docs [here](https://radix-ui.com/primitives/docs/components/collapsible).

25
Versions
MIT
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

hadihallakchancestricklandmark-workosnpm-workos

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Build-env metadata change on trusted high-volume radix package; not a risk signal. ai
provenance publisher-changed AI (provenance): Known Radix UI team transition to chancestrickland (WorkOS); stable for this package. ai
maintainer-change maintainer-added AI (maintainer-change): chancestrickland and mark-workos are known WorkOS/Radix maintainers. ai
maintainer-change maintainer-removed AI (maintainer-change): Reflects organizational transition at Radix/WorkOS; expected. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy due to monorepo restructuring; not suspicious for this package. ai
bogus-package bogus-package AI (bogus-package): Radix UI primitives are well-known; sparse README is normal for scoped sub-packages. ai

Versions (showing 25 of 25)

Version Deps Published
1.1.20 8 / 7
1.1.19 8 / 7
1.1.18 8 / 7
1.1.17 8 / 7
1.1.16 8 / 7
1.1.15 8 / 7
1.1.14 8 / 7
1.1.13 8 / 7
1.1.12 8 / 9
1.1.11 8 / 9
1.1.10 8 / 9
1.1.9 8 / 9
1.1.8 8 / 9
1.1.7 8 / 9
1.1.6 8 / 9
1.1.5 8 / 9
1.1.4 8 / 8
1.1.3 8 / 8
1.1.2 8 / 0
1.1.1 8 / 0
1.1.0 8 / 0
1.0.3 9 / 0
1.0.2 9 / 0
1.0.1 9 / 0
1.0.0 9 / 0

v1.1.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.8

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.7

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.6

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.5

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: benoitgrelard → chancestrickland (on 2024-10-01) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2024-10-01. This could indicate a legitimate maintainer transition or an account compromise.

v1.1.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: benoitgrelard → vladmoroz (on 2024-06-19, known maintainer) provenance

This version was published by a different npm account (vladmoroz) than the most recent previously approved version (benoitgrelard) on 2024-06-19, but vladmoroz is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.