← Home

@radix-ui/react-radio-group

View docs [here](https://radix-ui.com/primitives/docs/components/radio-group).

85
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

hadihallakchancestricklandmark-workosnpm-workos

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Monorepo primitive with minimal README/keywords; stable FP for this package. ai
provenance publisher-changed AI (provenance): Publisher change reflects a legitimate internal Radix UI/WorkOS team transition; chancestrickland is a long-standing ecosystem participant with strong approval history. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers chancestrickland and mark-workos are consistent with the Radix UI/WorkOS organization; legitimate team restructuring. ai
maintainer-change maintainer-removed AI (maintainer-change): Removed maintainers are consistent with a legitimate internal team transition at WorkOS/Radix UI, not a hostile takeover. ai
npm-metadata no-description AI (npm-metadata): Early Radix UI primitive packages did not include descriptions; this is a stable pattern for this package family, not a malware indicator. ai
dependencies unvetted-dep:@radix-ui/react-roving-focus AI (dependencies): @radix-ui/react-roving-focus is a sibling package from the same radix-ui/primitives monorepo; not a suspicious dependency. ai

Versions (showing 85 of 85)

Hide prereleases
Version Deps Published
1.4.7 9 / 7
1.4.6 9 / 7
1.4.5 9 / 7
1.4.4 9 / 7
1.4.3 10 / 7
1.4.2 10 / 7
1.4.1 10 / 7
1.4.0 10 / 7
1.3.8 10 / 9
1.3.7 10 / 9
1.3.6 10 / 9
1.3.5 10 / 9
1.3.4 10 / 9
1.3.1 10 / 9
1.3.0 10 / 9
1.2.4 10 / 8
1.2.3 10 / 8
1.2.2 10 / 0
1.2.1 10 / 0
1.2.0 10 / 0
1.1.3 11 / 0
1.1.2 11 / 0
1.1.1 11 / 0
1.1.0 11 / 0
1.0.0 12 / 0
0.1.5 11 / 0
0.1.4 11 / 0
0.1.3 11 / 0
0.1.2 11 / 0
0.1.1 11 / 0
0.1.0 11 / 0
0.0.19 13 / 0
0.0.18 13 / 0
0.0.17 14 / 0
0.0.16 12 / 0
0.0.15 12 / 0
0.0.14 11 / 0
0.0.13 11 / 0
0.0.12 11 / 0
0.0.11 11 / 0
0.0.10 11 / 0
0.0.9 10 / 0
0.0.8 10 / 0
0.0.7 10 / 0
0.0.6 7 / 0
0.0.5 7 / 0
0.0.4 7 / 0
0.0.3 7 / 0
0.0.2 7 / 0
0.0.1 6 / 1
1.3.9-rc.1766004502650 10 / 9
1.3.9-rc.1762291353631 10 / 9
1.3.9-rc.1762290574118 10 / 9
1.3.8-rc.1761760880074 10 / 9
1.3.8-rc.1761757765388 10 / 9
1.3.8-rc.1761752560860 10 / 9
1.3.8-rc.1761750294484 10 / 9
1.3.8-rc.1761750045307 10 / 9
1.3.8-rc.1761621280215 10 / 9
1.3.8-rc.1761620575619 10 / 9
1.3.8-rc.1761619701743 10 / 9
1.3.8-rc.1761615925003 10 / 9
1.3.8-rc.1761614930803 10 / 9
1.3.8-rc.1761614469962 10 / 9
1.3.8-rc.1761582029795 10 / 9
1.3.8-rc.1761327012562 10 / 9
1.3.8-rc.1755205432459 10 / 9
1.3.8-rc.1755201399387 10 / 9
1.3.8-rc.1755118410828 10 / 9
1.3.8-rc.1755114563302 10 / 9
1.3.8-rc.1752791004720 10 / 9
1.3.8-rc.1752166910601 10 / 9
1.3.8-rc.1752166434368 10 / 9
1.3.8-rc.1752166197873 10 / 9
1.3.8-rc.1752165236204 10 / 9
1.3.7-rc.1747678980544 10 / 9
1.3.7-rc.1746560904918 10 / 9
1.3.5-rc.1746466567086 10 / 9
1.3.5-rc.1746075822931 10 / 9
1.3.5-rc.1746053194630 10 / 9
1.3.5-rc.1746044551800 10 / 9
1.3.5-rc.1745972185559 10 / 9
1.3.5-rc.1745439717073 10 / 9
1.3.5-rc.1745345395380 10 / 9
1.3.4-rc.1745339201309 10 / 9

v1.4.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.4

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.1

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.