← Home

@radix-ui/react-toggle-group

View docs [here](https://radix-ui.com/primitives/docs/components/toggle-group).

43
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

hadihallakchancestricklandmark-workosnpm-workos

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Build-env metadata change on a trusted first-party radix package; no malicious behavior. ai
npm-metadata no-description AI (npm-metadata): Radix UI monorepo packages routinely have minimal descriptions; stable FP. ai
bogus-package bogus-package AI (bogus-package): Low-signal heuristics on a 44M-download established package; stable FP. ai
provenance no-provenance AI (provenance): Radix UI packages historically publish without Sigstore provenance; consistent with all prior versions of this package. ai
provenance publisher-changed AI (provenance): Publisher change reflects legitimate Radix UI / WorkOS team restructuring; chancestrickland is a long-standing, well-approved publisher in the ecosystem. ai
phantom-deps phantom-dep:@radix-ui/primitive AI (phantom-deps): Same-org dependency declared but used indirectly; consistent with Radix UI's internal package structure. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers (andy-hook, hadihallak, chancestrickland, mark-workos) are consistent with the WorkOS team maintaining Radix UI primitives. ai
maintainer-change maintainer-removed AI (maintainer-change): Removed maintainers reflect a legitimate team transition within the Radix UI / WorkOS organization, not a hostile takeover. ai

Versions (showing 43 of 43)

Hide prereleases
Version Deps Published
1.1.19 7 / 7
1.1.18 7 / 7
1.1.17 7 / 7
1.1.16 7 / 7
1.1.15 7 / 7
1.1.14 7 / 7
1.1.13 7 / 7
1.1.12 7 / 7
1.1.11 7 / 9
1.1.10 7 / 9
1.1.9 7 / 9
1.1.8 7 / 9
1.1.7 7 / 9
1.1.6 7 / 9
1.1.5 7 / 9
1.1.4 7 / 9
1.1.3 7 / 8
1.1.2 7 / 8
1.1.1 7 / 0
1.1.0 7 / 0
1.0.4 8 / 0
1.0.3 8 / 0
1.0.2 8 / 0
1.0.1 8 / 0
1.0.0 8 / 0
0.1.5 7 / 0
0.1.4 7 / 0
0.1.3 7 / 0
0.1.2 7 / 0
0.1.1 7 / 0
0.1.0 7 / 0
0.0.11 9 / 0
0.0.10 9 / 0
0.0.9 9 / 0
0.0.8 9 / 0
0.0.7 9 / 0
0.0.6 8 / 0
0.0.5 8 / 0
0.0.4 8 / 0
0.0.3 8 / 0
0.0.2 8 / 0
0.0.1 7 / 0
1.1.11-rc.1761752560860 7 / 9

v1.1.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.16

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v1.1.15

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.14

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.10

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.9

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.8

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.7

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.6

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.5

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.4

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.