← Home

@radix-ui/react-radio-group

View docs [here](https://radix-ui.com/primitives/docs/components/radio-group).

50
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

hadihallakchancestricklandmark-workosnpm-workos

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Monorepo primitive with minimal README/keywords; stable FP for this package. ai
provenance publisher-changed AI (provenance): Publisher change reflects a legitimate internal Radix UI/WorkOS team transition; chancestrickland is a long-standing ecosystem participant with strong approval history. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers chancestrickland and mark-workos are consistent with the Radix UI/WorkOS organization; legitimate team restructuring. ai
maintainer-change maintainer-removed AI (maintainer-change): Removed maintainers are consistent with a legitimate internal team transition at WorkOS/Radix UI, not a hostile takeover. ai
npm-metadata no-description AI (npm-metadata): Early Radix UI primitive packages did not include descriptions; this is a stable pattern for this package family, not a malware indicator. ai
dependencies unvetted-dep:@radix-ui/react-roving-focus AI (dependencies): @radix-ui/react-roving-focus is a sibling package from the same radix-ui/primitives monorepo; not a suspicious dependency. ai

Versions (showing 50 of 50)

Show 35 prereleases
Version Deps Published
1.4.7 9 / 7
1.4.6 9 / 7
1.4.5 9 / 7
1.4.4 9 / 7
1.4.3 10 / 7
1.4.2 10 / 7
1.4.1 10 / 7
1.4.0 10 / 7
1.3.8 10 / 9
1.3.7 10 / 9
1.3.6 10 / 9
1.3.5 10 / 9
1.3.4 10 / 9
1.3.1 10 / 9
1.3.0 10 / 9
1.2.4 10 / 8
1.2.3 10 / 8
1.2.2 10 / 0
1.2.1 10 / 0
1.2.0 10 / 0
1.1.3 11 / 0
1.1.2 11 / 0
1.1.1 11 / 0
1.1.0 11 / 0
1.0.0 12 / 0
0.1.5 11 / 0
0.1.4 11 / 0
0.1.3 11 / 0
0.1.2 11 / 0
0.1.1 11 / 0
0.1.0 11 / 0
0.0.19 13 / 0
0.0.18 13 / 0
0.0.17 14 / 0
0.0.16 12 / 0
0.0.15 12 / 0
0.0.14 11 / 0
0.0.13 11 / 0
0.0.12 11 / 0
0.0.11 11 / 0
0.0.10 11 / 0
0.0.9 10 / 0
0.0.8 10 / 0
0.0.7 10 / 0
0.0.6 7 / 0
0.0.5 7 / 0
0.0.4 7 / 0
0.0.3 7 / 0
0.0.2 7 / 0
0.0.1 6 / 1

v1.4.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.4

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.1

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.