@radix-ui/react-toolbar
View docs [here](https://radix-ui.com/primitives/docs/components/toolbar).
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Radix UI primitives are a well-established, widely-downloaded package family. Lack of Sigstore provenance is a process gap, not a security risk for this trusted publisher. | ai | |
| provenance | publisher-changed | AI (provenance): vladmoroz is a known Radix UI core maintainer; transition from benoitgrelard is a legitimate team handoff within the same org. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Radix UI monorepo sub-packages commonly omit descriptions; not indicative of malice for this established package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Radix UI sub-package with 6.8M weekly downloads and 1891 days of history. Spam signals are false positives: known maintainer, legitimate monorepo component, short README is standard for this package family. | ai |
Versions (showing 78 of 78)
v1.1.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.