← Home

@simoncomputing/mui-bueno-v3

A React component library based on [Material UI](https://mui.com/material-ui) components with built-in support for [React Hook Form](https://react-hook-form.com/). Rebuilt & redesigned based on the original [mui-bueno](https://www.npmjs.com/package/@simon

5
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

simon.woolat.trantyra.krehbiel.scthomas.campbellmrigsbee

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Org-published component library; lack of Sigstore provenance is common and not a risk signal here. ai
phantom-deps phantom-dep:google-maps AI (phantom-deps): google-maps declared as dependency for Google Maps integration; phantom detection is a false positive here. ai
phantom-deps phantom-dep:@types/google.maps AI (phantom-deps): Type-only package loaded by convention; not directly imported in source. ai
phantom-deps phantom-dep:@tiptap/starter-kit AI (phantom-deps): Tiptap extension declared for consumer use; stable false positive for this library. ai
phantom-deps phantom-dep:autosuggest-highlight AI (phantom-deps): Utility declared as dependency for autocomplete UI; phantom detection is a false positive. ai
phantom-deps phantom-dep:@tiptap/extension-image AI (phantom-deps): Tiptap extension; stable false positive for this rich-text component library. ai
phantom-deps phantom-dep:@tiptap/pm AI (phantom-deps): Tiptap peer/extension packages are commonly declared but loaded transitively; stable false positive for this component library. ai
phantom-deps phantom-dep:@tiptap/extension-heading AI (phantom-deps): Tiptap extension; stable false positive for this rich-text component library. ai
phantom-deps phantom-dep:@types/autosuggest-highlight AI (phantom-deps): Type-only package loaded by convention; not directly imported in source. ai
phantom-deps phantom-dep:@tiptap/extension-bubble-menu AI (phantom-deps): Tiptap extension; stable false positive for this rich-text component library. ai
phantom-deps phantom-dep:@tiptap/extension-floating-menu AI (phantom-deps): Tiptap extension; stable false positive for this rich-text component library. ai
phantom-deps phantom-dep:@tiptap/extension-table AI (phantom-deps): Tiptap extension; stable false positive for this rich-text component library. ai

Versions (showing 5 of 5)

Version Deps Published
0.2.10 47 / 34
0.2.9 47 / 34
0.2.7 47 / 34
0.1.13 49 / 34
0.1.12 49 / 34

v0.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.