@schemavaults/ui
React.js UI components for SchemaVaults frontend applications
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@radix-ui/react-avatar | AI (dependencies): Well-known Radix UI primitive; stable false positive for this UI library. | ai | |
| dependencies | unvetted-dep:@radix-ui/react-hover-card | AI (dependencies): Well-known Radix UI primitive; stable false positive for this UI library. | ai | |
| dependencies | unvetted-dep:@schemavaults/theme | AI (dependencies): Internal scoped package from same org; consistent with this package's purpose. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a peer/runtime dep commonly declared but re-exported; stable false positive for a UI component library. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI/CD with SLSA provenance; rapid publishes are expected in this pipeline. | ai | |
| phantom-deps | phantom-dep:@hookform/resolvers | AI (phantom-deps): UI component library; resolvers likely referenced in config/type files, stable false positive. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped org package @schemavaults/ui; not a typosquat of uuid. | ai | |
| phantom-deps | phantom-dep:@emotion/is-prop-valid | AI (phantom-deps): Used transitively by framer-motion; config-only reference is expected pattern. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped org package @schemavaults/ui; not a typosquat of pg. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped org package @schemavaults/ui; not a typosquat of qs. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped org package @schemavaults/ui; not a typosquat of joi. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped org package @schemavaults/ui; not a typosquat of yup. | ai |
Versions (showing 51 of 138)
| Version | Deps | Published |
|---|---|---|
| 0.90.0 | 33 / 32 | |
| 0.89.0 | 33 / 32 | |
| 0.88.1 | 33 / 32 | |
| 0.87.1 | 33 / 32 | |
| 0.87.0 | 33 / 32 | |
| 0.86.2 | 33 / 32 | |
| 0.85.4 | 33 / 32 | |
| 0.85.3 | 33 / 32 | |
| 0.85.2 | 33 / 32 | |
| 0.84.0 | 33 / 32 | |
| 0.83.0 | 33 / 32 | |
| 0.82.0 | 33 / 32 | |
| 0.81.0 | 33 / 32 | |
| 0.80.0 | 33 / 32 | |
| 0.79.4 | 33 / 32 | |
| 0.79.3 | 33 / 32 | |
| 0.79.2 | 33 / 32 | |
| 0.79.1 | 33 / 32 | |
| 0.78.3 | 33 / 32 | |
| 0.78.0 | 33 / 32 | |
| 0.77.0 | 33 / 32 | |
| 0.76.0 | 33 / 32 | |
| 0.75.0 | 33 / 32 | |
| 0.74.0 | 33 / 32 | |
| 0.73.0 | 33 / 32 | |
| 0.72.3 | 33 / 32 | |
| 0.72.2 | 33 / 32 | |
| 0.72.1 | 33 / 28 | |
| 0.71.1 | 33 / 28 | |
| 0.70.0 | 33 / 28 | |
| 0.69.0 | 33 / 28 | |
| 0.68.1 | 33 / 28 | |
| 0.67.0 | 33 / 28 | |
| 0.66.0 | 33 / 28 | |
| 0.65.0 | 33 / 28 | |
| 0.64.0 | 33 / 28 | |
| 0.63.0 | 33 / 28 | |
| 0.62.0 | 33 / 28 | |
| 0.61.0 | 33 / 28 | |
| 0.60.0 | 33 / 28 | |
| 0.59.1 | 33 / 28 | |
| 0.57.1 | 33 / 28 | |
| 0.56.2 | 33 / 28 | |
| 0.55.0 | 33 / 28 | |
| 0.54.3 | 33 / 28 | |
| 0.54.2 | 33 / 28 | |
| 0.54.1 | 33 / 28 | |
| 0.53.1 | 33 / 28 | |
| 0.52.6 | 33 / 28 | |
| 0.52.5 | 33 / 28 | |
| 0.52.4 | 33 / 28 |
v0.90.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.89.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.88.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.87.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.87.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.86.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.85.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.85.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.85.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.84.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.83.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.82.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.80.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.79.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.79.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.60.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.59.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.57.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.55.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.54.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.54.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.53.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.52.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.52.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.52.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.