@reach/utils
Internal, shared utilities for Reach UI.
45
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
ryanflorencemjacksonchancestricklandblainekasten
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/warning | AI (phantom-deps): @types/warning is a type declaration package, not a runtime import. Phantom-dep finding is a known false positive for @types/* packages. | ai | |
| source-diff | net-exec-file:dist/reach-utils.cjs.dev.js | AI (source-diff): Standard Rollup CJS bundle for a React utility library. 'Network' signal is from JSDoc URL comments; 'exec' signal is from standard interop helpers. No actual network calls or dynamic code execution. | ai | |
| source-diff | net-exec-file:dist/reach-utils.cjs.prod.js | AI (source-diff): Standard Rollup CJS production bundle. Same false-positive pattern as dev bundle — JSDoc URLs and interop boilerplate, not malware. | ai | |
| source-diff | net-exec-file:dist/reach-utils.esm.js | AI (source-diff): Standard Rollup ESM bundle. Same false-positive pattern — JSDoc URLs and module interop patterns, not actual network or exec activity. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard TypeScript runtime helper; phantom-dep finding is expected for this type of package. | ai | |
| provenance | missing-githead | AI (provenance): Missing gitHead reflects a CI/CD environment change for this well-established package; no security implication given clean package contents and trusted publisher. | ai | |
| provenance | no-provenance | AI (provenance): Informational only; many established packages lack Sigstore provenance. Not a security risk for this well-known package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): chancestrickland is the legitimate Reach UI maintainer with 1797 approved packages. Internal utility package naturally has sparse README and no keywords. | ai | |
| provenance | publisher-changed | AI (provenance): ryanflorence and mjackson are co-maintainers of Reach UI; this transition is a known, legitimate handoff between collaborators on the same project. | ai | |
| email-domain | unclaimed-email:ryanflorence | AI (email-domain): The author field uses '@ryanflorence' as a Twitter-handle placeholder, not a real email address. No actual email domain is at risk of hijacking. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): mjackson is Michael Jackson, co-author of Reach UI alongside Ryan Florence. Addition is a legitimate, expected co-maintainer transition. | ai |
Versions (showing 45 of 45)
| Version | Deps | Published |
|---|---|---|
| 0.18.0 | 0 / 6 | |
| 0.17.0 | 2 / 2 | |
| 0.16.0 | 2 / 2 | |
| 0.15.3 | 2 / 2 | |
| 0.15.2 | 2 / 2 | |
| 0.15.0 | 2 / 2 | |
| 0.14.0 | 3 / 2 | |
| 0.13.2 | 3 / 2 | |
| 0.13.1 | 3 / 2 | |
| 0.13.0 | 3 / 0 | |
| 0.12.1 | 3 / 0 | |
| 0.12.0 | 3 / 0 | |
| 0.11.2 | 3 / 0 | |
| 0.11.1 | 3 / 0 | |
| 0.11.0 | 3 / 0 | |
| 0.10.5 | 3 / 0 | |
| 0.10.4 | 3 / 0 | |
| 0.10.3 | 3 / 0 | |
| 0.10.2 | 3 / 0 | |
| 0.10.1 | 3 / 0 | |
| 0.10.0 | 2 / 0 | |
| 0.9.0 | 2 / 0 | |
| 0.8.6 | 2 / 0 | |
| 0.8.5 | 2 / 0 | |
| 0.8.4 | 2 / 0 | |
| 0.8.3 | 2 / 0 | |
| 0.8.2 | 2 / 0 | |
| 0.8.0 | 0 / 0 | |
| 0.7.4 | 0 / 0 | |
| 0.7.3 | 0 / 0 | |
| 0.7.2 | 0 / 0 | |
| 0.7.1 | 0 / 0 | |
| 0.7.0 | 0 / 0 | |
| 0.6.4 | 0 / 0 | |
| 0.6.1 | 0 / 0 | |
| 0.5.0 | 0 / 0 | |
| 0.4.0 | 0 / 0 | |
| 0.3.0 | 0 / 0 | |
| 0.2.3 | 0 / 0 | |
| 0.2.2 | 0 / 0 | |
| 0.2.1 | 0 / 0 | |
| 0.2.0 | 0 / 0 | |
| 0.1.2 | 0 / 0 | |
| 0.1.1 | 0 / 0 | |
| 0.1.0 | 0 / 0 |