← Home

@reduxjs/toolkit

31
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

acemarketimdorrgaearonphryneascrutchcorneskimojo

Keywords

reduxreactstartertoolkitreducersliceimmerimmutableredux-toolkittanstack-intent

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance regressed-provenance AI (provenance): Manual publish by known maintainer acemarke; benign build-only diff, no malicious behavior. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get() in combineSlices.ts is used inside a Proxy get trap — the canonical idiomatic pattern for forwarding property access. Not obfuscation; stable false positive for this package. ai

Versions (showing 31 of 31)

Version Deps Published
2.12.0 6 / 48
2.11.2 6 / 54
2.11.1 6 / 54
2.11.0 6 / 54
2.10.1 6 / 54
2.10.0 6 / 54
2.9.2 6 / 54
2.9.1 6 / 54
2.9.0 6 / 54
2.8.2 6 / 54
2.8.1 6 / 54
2.8.0 6 / 54
2.7.0 6 / 54
2.6.1 4 / 53
2.6.0 4 / 53
2.5.1 4 / 52
2.5.0 4 / 52
2.4.0 4 / 50
2.3.0 4 / 50
2.2.8 4 / 50
2.2.7 4 / 50
2.2.6 4 / 45
2.2.5 4 / 45
2.2.4 4 / 45
2.2.3 4 / 45
2.2.2 4 / 45
2.2.1 4 / 45
2.2.0 4 / 45
2.1.0 4 / 43
2.0.1 4 / 43
2.0.0 4 / 43

v2.7.0

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: phryneas → acemarke (on 2025-04-16, known maintainer) provenance

This version was published by a different npm account (acemarke) than the most recent previously approved version (phryneas) on 2025-04-16, but acemarke is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.6.1

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: phryneas → acemarke (on 2025-03-07, known maintainer) provenance

This version was published by a different npm account (acemarke) than the most recent previously approved version (phryneas) on 2025-03-07, but acemarke is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.6.0

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: phryneas → acemarke (on 2025-02-23, known maintainer) provenance

This version was published by a different npm account (acemarke) than the most recent previously approved version (phryneas) on 2025-02-23, but acemarke is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.5.1

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: phryneas → acemarke (on 2025-01-26, known maintainer) provenance

This version was published by a different npm account (acemarke) than the most recent previously approved version (phryneas) on 2025-01-26, but acemarke is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.5.0

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: phryneas → acemarke (on 2024-12-11, known maintainer) provenance

This version was published by a different npm account (acemarke) than the most recent previously approved version (phryneas) on 2024-12-11, but acemarke is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.4.0

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: phryneas → acemarke (on 2024-11-28, known maintainer) provenance

This version was published by a different npm account (acemarke) than the most recent previously approved version (phryneas) on 2024-11-28, but acemarke is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.3.0

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: phryneas → acemarke (on 2024-10-14, known maintainer) provenance

This version was published by a different npm account (acemarke) than the most recent previously approved version (phryneas) on 2024-10-14, but acemarke is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.2.8

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: phryneas → acemarke (on 2024-10-08, known maintainer) provenance

This version was published by a different npm account (acemarke) than the most recent previously approved version (phryneas) on 2024-10-08, but acemarke is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.2.7

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: phryneas → acemarke (on 2024-07-27, known maintainer) provenance

This version was published by a different npm account (acemarke) than the most recent previously approved version (phryneas) on 2024-07-27, but acemarke is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.2.6

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: acemarke → phryneas (on 2024-06-29, known maintainer) provenance

This version was published by a different npm account (phryneas) than the most recent previously approved version (acemarke) on 2024-06-29, but phryneas is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.3

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: acemarke → phryneas (on 2024-03-31, now via trusted publisher with provenance) provenance

This version was published by a different npm account (phryneas) than the most recent previously approved version (acemarke) on 2024-03-31, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.2.2

2 findings
INFO Provenance attestation missing — previous versions had it provenance

[Accepted risk] This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.

INFO Publisher changed: phryneas → acemarke (on 2024-03-21, known maintainer) provenance

This version was published by a different npm account (acemarke) than the most recent previously approved version (phryneas) on 2024-03-21, but acemarke is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: acemarke → phryneas (on 2024-02-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (phryneas) than the most recent previously approved version (acemarke) on 2024-02-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.1.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: acemarke → phryneas (on 2024-01-24, now via trusted publisher with provenance) provenance

This version was published by a different npm account (phryneas) than the most recent previously approved version (acemarke) on 2024-01-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.