← Home

@rjsf/chakra-ui

Chakra UI theme, fields, and widgets for react-jsonschema-form

21
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

epicfaacerjsf-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@ark-ui/react AI (phantom-deps): Config-referenced dependency, not a real phantom import concern. ai
phantom-deps phantom-dep:@zag-js/react AI (phantom-deps): Config-referenced dependency, not a real phantom import concern. ai
phantom-deps phantom-dep:@emotion/memoize AI (phantom-deps): Config-referenced dependency, not a real phantom import concern. ai
provenance publisher-changed AI (provenance): rjsf-team migrated publishing to GitHub Actions CI with SLSA attestation; stable pattern for this package going forward. ai
phantom-deps phantom-dep:react-select AI (phantom-deps): react-select is a declared runtime dependency; phantom-dep heuristic fires but it's legitimately used. ai

Versions (showing 21 of 21)

Version Deps Published
6.7.0 9 / 8
6.6.2 3 / 8
6.6.1 3 / 9
6.6.0 3 / 9
6.5.3 3 / 11
6.5.2 3 / 11
6.5.1 3 / 11
6.5.0 3 / 11
6.4.2 3 / 11
6.4.1 3 / 11
6.4.0 3 / 11
6.3.1 3 / 11
6.3.0 3 / 11
6.2.5 3 / 11
6.2.4 3 / 11
6.1.2 3 / 11
6.1.1 3 / 11
6.1.0 3 / 11
6.0.2 3 / 11
6.0.1 3 / 11
6.0.0 3 / 11

v6.7.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.