@schemavaults/ui
React.js UI components for SchemaVaults frontend applications
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@radix-ui/react-avatar | AI (dependencies): Well-known Radix UI primitive; stable false positive for this UI library. | ai | |
| dependencies | unvetted-dep:@radix-ui/react-hover-card | AI (dependencies): Well-known Radix UI primitive; stable false positive for this UI library. | ai | |
| dependencies | unvetted-dep:@schemavaults/theme | AI (dependencies): Internal scoped package from same org; consistent with this package's purpose. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a peer/runtime dep commonly declared but re-exported; stable false positive for a UI component library. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI/CD with SLSA provenance; rapid publishes are expected in this pipeline. | ai | |
| phantom-deps | phantom-dep:@hookform/resolvers | AI (phantom-deps): UI component library; resolvers likely referenced in config/type files, stable false positive. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped org package @schemavaults/ui; not a typosquat of uuid. | ai | |
| phantom-deps | phantom-dep:@emotion/is-prop-valid | AI (phantom-deps): Used transitively by framer-motion; config-only reference is expected pattern. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped org package @schemavaults/ui; not a typosquat of pg. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped org package @schemavaults/ui; not a typosquat of qs. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped org package @schemavaults/ui; not a typosquat of joi. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped org package @schemavaults/ui; not a typosquat of yup. | ai |
Versions (showing 38 of 138)
| Version | Deps | Published |
|---|---|---|
| 0.15.0 | 35 / 31 | |
| 0.14.12 | 35 / 31 | |
| 0.14.11 | 35 / 30 | |
| 0.14.10 | 35 / 30 | |
| 0.14.9 | 34 / 30 | |
| 0.14.8 | 34 / 30 | |
| 0.14.7 | 34 / 30 | |
| 0.14.6 | 34 / 30 | |
| 0.14.5 | 34 / 30 | |
| 0.14.4 | 33 / 30 | |
| 0.14.3 | 33 / 30 | |
| 0.14.2 | 33 / 30 | |
| 0.14.0 | 33 / 30 | |
| 0.13.15 | 33 / 30 | |
| 0.13.14 | 33 / 30 | |
| 0.13.13 | 33 / 30 | |
| 0.13.12 | 32 / 30 | |
| 0.13.10 | 32 / 30 | |
| 0.13.9 | 32 / 30 | |
| 0.13.8 | 32 / 30 | |
| 0.13.6 | 32 / 30 | |
| 0.13.5 | 32 / 30 | |
| 0.13.4 | 32 / 30 | |
| 0.13.3 | 32 / 29 | |
| 0.13.2 | 32 / 29 | |
| 0.13.1 | 32 / 29 | |
| 0.13.0 | 32 / 29 | |
| 0.12.10 | 32 / 29 | |
| 0.12.9 | 32 / 29 | |
| 0.12.4 | 32 / 29 | |
| 0.12.3 | 32 / 29 | |
| 0.12.2 | 32 / 29 | |
| 0.12.0 | 32 / 29 | |
| 0.11.133 | 33 / 22 | |
| 0.11.131 | 33 / 22 | |
| 0.11.130 | 33 / 22 | |
| 0.11.129 | 33 / 22 | |
| 0.11.128 | 32 / 22 |
v0.15.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.133
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.131
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.130
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.129
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.128
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.