No SLSA provenancenpm registry signaturesgitHead linked
Without SLSA provenance there is no cryptographic link between this
tarball and the public source, so a manually published version cannot
be tied back to a reviewed commit.
Maintainers
devongovettaspro83
Accepted risks
Findings the reviewer chose to accept rather than block on.
Source
Rule
Reason
Accepted by
When
phantom-deps
phantom-dep:@react-aria/selection
AI (phantom-deps): Legitimate monorepo cross-dependency; properly declared in package.json despite not being directly imported in all files.
ai
phantom-deps
phantom-dep:@react-stately/collections
AI (phantom-deps): Legitimate monorepo cross-dependency; properly declared in package.json despite not being directly imported in all files.
ai
bogus-package
bogus-package
AI (bogus-package): Scoped library package in monorepo; minimal README and no keywords are typical for component libraries relying on parent documentation.