@radix-ui/react-collection
This is an internal utility, not intended for public usage.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Build env change on official Radix package; no malicious behavior. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Bundling/build-tool shift on trusted package, not injected payload. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Terse README is normal for Radix mono-repo primitives. | ai | |
| provenance | publisher-changed | AI (provenance): vladmoroz is a known Radix UI maintainer with extensive history (503 approved packages). This is a legitimate org-internal maintainer transition, not a takeover. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-primitive | AI (phantom-deps): @radix-ui/react-primitive is a declared runtime dependency in the same org scope; phantom-dep detection is a false positive for this monorepo package. | ai |
Versions (showing 40 of 40)
| Version | Deps | Published |
|---|---|---|
| 1.1.15 | 4 / 7 | |
| 1.1.14 | 4 / 7 | |
| 1.1.13 | 4 / 7 | |
| 1.1.12 | 4 / 7 | |
| 1.1.11 | 4 / 7 | |
| 1.1.10 | 4 / 7 | |
| 1.1.9 | 4 / 7 | |
| 1.1.8 | 4 / 9 | |
| 1.1.7 | 4 / 9 | |
| 1.1.6 | 4 / 9 | |
| 1.1.5 | 4 / 9 | |
| 1.1.4 | 4 / 9 | |
| 1.1.3 | 4 / 8 | |
| 1.1.2 | 4 / 8 | |
| 1.1.1 | 4 / 0 | |
| 1.1.0 | 4 / 0 | |
| 1.0.3 | 5 / 0 | |
| 1.0.2 | 5 / 0 | |
| 1.0.1 | 5 / 0 | |
| 1.0.0 | 5 / 0 | |
| 0.1.4 | 5 / 0 | |
| 0.1.3 | 5 / 0 | |
| 0.1.2 | 5 / 0 | |
| 0.1.1 | 5 / 0 | |
| 0.1.0 | 4 / 0 | |
| 0.0.15 | 3 / 0 | |
| 0.0.14 | 3 / 0 | |
| 0.0.13 | 3 / 0 | |
| 0.0.12 | 3 / 0 | |
| 0.0.11 | 3 / 0 | |
| 0.0.10 | 3 / 0 | |
| 0.0.9 | 3 / 0 | |
| 0.0.8 | 3 / 0 | |
| 0.0.7 | 3 / 0 | |
| 0.0.6 | 2 / 0 | |
| 0.0.5 | 1 / 0 | |
| 0.0.4 | 1 / 0 | |
| 0.0.3 | 1 / 0 | |
| 0.0.2 | 1 / 0 | |
| 0.0.1 | 1 / 1 |
v1.1.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.