@radix-ui/react-popper
This is an internal utility, not intended for public usage.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Publish-env change on a canonical high-trust package; no behavioral risk. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Radix monorepo packages ship no description; stable FP. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Canonical radix-ui primitive, 60.5M downloads, SLSA-attested; thin README/no-keywords are FP for monorepo sub-packages. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-use-rect | AI (phantom-deps): Same-org dep used transitively/via re-export; benign for this package. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 1.3.7 | 10 / 8 | |
| 1.3.6 | 10 / 8 | |
| 1.3.5 | 10 / 8 | |
| 1.3.4 | 10 / 8 | |
| 1.3.3 | 10 / 8 | |
| 1.3.2 | 10 / 8 | |
| 1.3.1 | 10 / 7 | |
| 1.3.0 | 10 / 7 | |
| 1.2.8 | 10 / 9 | |
| 1.2.7 | 10 / 9 | |
| 1.2.6 | 10 / 9 | |
| 1.2.5 | 10 / 9 | |
| 1.2.4 | 10 / 9 | |
| 1.2.3 | 10 / 8 | |
| 1.2.1 | 10 / 0 | |
| 1.2.0 | 10 / 0 | |
| 1.1.3 | 11 / 0 | |
| 1.1.2 | 11 / 0 | |
| 1.1.1 | 11 / 0 | |
| 1.1.0 | 11 / 0 | |
| 1.0.1 | 10 / 0 | |
| 1.0.0 | 10 / 0 |
v1.3.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.3
2 findings[Reject — re-review on republish] (prior reject: AI (bogus-package): Inflated first semver, no keywords, and thin README are consistent with an impersonation package masquerading as the legitimate @radix-ui/react-popper. Generalizes across all versi) Matched 3 signal(s), weighted score 4: • [S_README_NO_CODE] Short README with no code block, no install instructions, and no usage/API section. • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_KEYWORDS] No keywords declared.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (chancestrickland) on 2026-06-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.2.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.
v1.2.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.
v1.2.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.
v1.2.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.
v1.2.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.