@rh-support/react-context
## Usage
10
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
seyedanujsijohnbargutippareekhaakankshabhendearajakjeudy100bkaletkinaregisonirh-ee-adpandeyrhn-support-vijadhav
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Established Red Hat org package; maintainer additions are routine team changes, no code or script changes accompany this version. | ai | |
| provenance | publisher-changed | AI (provenance): arajak is an established Red Hat publisher with 47 approved packages; transition appears legitimate within the rh-support org. | ai | |
| provenance | no-provenance | AI (provenance): Internal Red Hat monorepo package; provenance via Sigstore CI/CD not configured for this org's pipeline. | ai | |
| dependencies | unvetted-dep:@cee-eng/hydrajs | AI (dependencies): Internal Red Hat/CEE engineering library; consistent with package's Red Hat origin and present across many versions. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Declared as peer/dep for React app context; referenced in config files only, not a real phantom dep issue for this package. | ai | |
| phantom-deps | phantom-dep:react-test-renderer | AI (phantom-deps): Test renderer declared as peer dep; config-file reference only, stable false positive. | ai | |
| phantom-deps | phantom-dep:react-router-dom | AI (phantom-deps): Same pattern — config-file reference only; stable false positive for this package. | ai |