@snack-uikit/fields
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Consistent across all versions of this package; publisher has 253 approved packages with no provenance issues. | ai | |
| dependencies | unvetted-dep:@snack-uikit/list | AI (dependencies): Same monorepo/publisher as parent; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@snack-uikit/slider | AI (dependencies): Same monorepo/publisher as parent; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@snack-uikit/tag | AI (dependencies): Same monorepo/publisher as parent; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@snack-uikit/skeleton | AI (dependencies): Same monorepo/publisher as parent; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@snack-uikit/color-picker | AI (dependencies): Same monorepo/publisher as parent; stable false positive for this package family. | ai | |
| dependencies | unvetted-dep:@snack-uikit/calendar | AI (dependencies): Same monorepo/publisher as parent; stable false positive for this package family. | ai |
Versions (showing 51 of 56)
| Version | Deps | Published |
|---|---|---|
| 0.56.2 | 22 / 2 | |
| 0.56.1 | 22 / 2 | |
| 0.56.0 | 22 / 2 | |
| 0.55.2 | 22 / 2 | |
| 0.55.1 | 22 / 2 | |
| 0.55.0 | 22 / 2 | |
| 0.53.1 | 22 / 2 | |
| 0.53.0 | 22 / 2 | |
| 0.51.17 | 22 / 2 | |
| 0.51.15 | 22 / 2 | |
| 0.51.13 | 22 / 2 | |
| 0.51.12 | 22 / 2 | |
| 0.51.7 | 22 / 2 | |
| 0.51.6 | 22 / 2 | |
| 0.51.5 | 22 / 2 | |
| 0.51.4 | 21 / 2 | |
| 0.51.3 | 21 / 2 | |
| 0.51.2 | 21 / 2 | |
| 0.51.1 | 21 / 2 | |
| 0.51.0 | 21 / 2 | |
| 0.50.0 | 21 / 2 | |
| 0.49.3 | 21 / 2 | |
| 0.49.2 | 21 / 2 | |
| 0.49.1 | 21 / 2 | |
| 0.49.0 | 21 / 2 | |
| 0.48.14 | 21 / 2 | |
| 0.48.13 | 21 / 2 | |
| 0.48.12 | 21 / 2 | |
| 0.48.11 | 21 / 2 | |
| 0.48.10 | 21 / 2 | |
| 0.48.9 | 21 / 2 | |
| 0.48.8 | 21 / 2 | |
| 0.48.7 | 21 / 2 | |
| 0.48.6 | 21 / 2 | |
| 0.48.5 | 21 / 2 | |
| 0.48.4 | 21 / 2 | |
| 0.48.3 | 21 / 2 | |
| 0.48.2 | 21 / 2 | |
| 0.48.1 | 21 / 2 | |
| 0.48.0 | 21 / 2 | |
| 0.47.4 | 21 / 2 | |
| 0.47.3 | 21 / 2 | |
| 0.47.2 | 21 / 2 | |
| 0.47.1 | 21 / 2 | |
| 0.47.0 | 21 / 2 | |
| 0.46.0 | 21 / 2 | |
| 0.45.0 | 21 / 2 | |
| 0.44.0 | 21 / 2 | |
| 0.43.0 | 21 / 2 | |
| 0.42.7 | 21 / 2 | |
| 0.42.6 | 21 / 2 |
v0.56.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.56.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.56.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.55.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.55.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.55.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.53.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.53.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.51.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.51.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.51.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.51.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.51.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.51.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.51.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.51.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.51.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.51.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.51.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.51.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.50.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.49.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.49.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.49.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.49.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.48.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.48.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.48.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.48.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.46.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.45.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.