@spscommerce/ds-react
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:axe-prop-types | AI (dependencies): axe-prop-types is a known accessibility utility; stable dependency for this design system package. | ai | |
| provenance | no-provenance | AI (provenance): Long-established package with 825 versions; no provenance has been a consistent pattern. | ai | |
| license | uncommon-license:UNLICENSED | AI (license): Proprietary internal SPS Commerce design system; UNLICENSED is intentional and consistent across versions. | ai | |
| phantom-deps | phantom-dep:axe-prop-types | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:tiny-invariant | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@react-aria/tabs | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@react-aria/focus | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@react-aria/utils | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@react-aria/button | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@react-aria/listbox | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@react-stately/list | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@react-aria/overlays | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:lodash.isplainobject | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@react-stately/select | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:scroll-into-view-if-needed | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@react-aria/select | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:nanoid | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): Bundled component library; deps consumed via build, not direct imports. | ai |
Versions (showing 100 of 241)
| Version | Deps | Published |
|---|---|---|
| 8.31.6 | 18 / 25 | |
| 8.31.5 | 18 / 25 | |
| 8.31.4 | 18 / 25 | |
| 8.31.3 | 18 / 25 | |
| 8.31.2 | 18 / 25 | |
| 8.31.1 | 18 / 25 | |
| 8.31.0 | 18 / 25 | |
| 8.30.1 | 18 / 25 | |
| 8.30.0 | 18 / 25 | |
| 8.29.10 | 18 / 25 | |
| 8.29.9 | 18 / 25 | |
| 8.29.8 | 18 / 25 | |
| 8.29.7 | 18 / 25 | |
| 8.29.6 | 18 / 25 | |
| 8.29.5 | 18 / 25 | |
| 8.29.4 | 18 / 25 | |
| 8.29.3 | 18 / 25 | |
| 8.29.2 | 18 / 25 | |
| 8.29.1 | 18 / 25 | |
| 8.29.0 | 18 / 25 | |
| 8.28.5 | 18 / 25 | |
| 8.28.4 | 18 / 25 | |
| 8.28.3 | 18 / 25 | |
| 8.28.2 | 18 / 24 | |
| 8.28.1 | 18 / 24 | |
| 8.28.0 | 18 / 24 | |
| 8.27.2 | 18 / 25 | |
| 8.27.1 | 18 / 25 | |
| 8.26.8 | 18 / 25 | |
| 8.26.7 | 18 / 25 | |
| 8.26.6 | 18 / 25 | |
| 8.26.5 | 18 / 25 | |
| 8.26.4 | 18 / 25 | |
| 8.26.3 | 18 / 25 | |
| 8.26.2 | 18 / 25 | |
| 8.26.1 | 18 / 25 | |
| 8.26.0 | 18 / 25 | |
| 8.25.0 | 18 / 25 | |
| 8.24.2 | 18 / 25 | |
| 8.24.0 | 18 / 25 | |
| 8.23.18 | 18 / 25 | |
| 8.23.17 | 18 / 25 | |
| 8.23.16 | 18 / 25 | |
| 8.23.15 | 18 / 25 | |
| 8.23.14 | 18 / 25 | |
| 8.23.13 | 18 / 25 | |
| 8.23.12 | 18 / 25 | |
| 8.23.11 | 18 / 25 | |
| 8.23.10 | 18 / 25 | |
| 8.23.9 | 18 / 25 | |
| 8.23.8 | 18 / 25 | |
| 8.23.7 | 18 / 25 | |
| 8.23.6 | 18 / 25 | |
| 8.23.5 | 18 / 25 | |
| 8.23.4 | 18 / 25 | |
| 8.23.3 | 18 / 25 | |
| 8.23.2 | 18 / 25 | |
| 8.23.1 | 18 / 25 | |
| 8.23.0 | 18 / 25 | |
| 8.22.1 | 18 / 25 | |
| 8.22.0 | 18 / 25 | |
| 8.21.5 | 18 / 25 | |
| 8.21.4 | 18 / 25 | |
| 8.21.3 | 18 / 25 | |
| 8.21.2 | 18 / 25 | |
| 8.21.1 | 18 / 25 | |
| 8.21.0 | 18 / 25 | |
| 8.20.17 | 18 / 25 | |
| 8.20.16 | 18 / 25 | |
| 8.20.15 | 18 / 25 | |
| 8.20.14 | 18 / 25 | |
| 8.20.13 | 18 / 25 | |
| 8.20.12 | 18 / 25 | |
| 8.20.11 | 18 / 25 | |
| 8.20.10 | 18 / 25 | |
| 8.20.9 | 18 / 25 | |
| 8.20.8 | 18 / 25 | |
| 8.20.7 | 18 / 25 | |
| 8.20.6 | 18 / 25 | |
| 8.20.5 | 18 / 25 | |
| 8.20.4 | 18 / 25 | |
| 8.20.3 | 18 / 25 | |
| 8.20.2 | 18 / 25 | |
| 8.20.1 | 18 / 25 | |
| 8.20.0 | 18 / 25 | |
| 8.19.12 | 18 / 25 | |
| 8.19.11 | 18 / 25 | |
| 8.19.10 | 18 / 25 | |
| 8.19.9 | 18 / 25 | |
| 8.19.8 | 18 / 25 | |
| 8.19.7 | 18 / 25 | |
| 8.19.6 | 18 / 25 | |
| 8.19.5 | 18 / 25 | |
| 8.19.4 | 18 / 25 | |
| 8.19.3 | 18 / 25 | |
| 8.19.2 | 18 / 25 | |
| 8.19.1 | 18 / 25 | |
| 8.19.0 | 18 / 25 | |
| 8.18.0 | 18 / 25 | |
| 8.17.2 | 18 / 25 |
v8.29.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.29.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.29.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.29.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.29.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.29.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.28.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.28.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.28.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.28.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.28.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.27.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.27.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.26.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.26.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.26.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.26.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.26.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.26.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.26.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.26.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.24.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.24.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.23.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.22.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.22.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.21.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.21.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.21.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.21.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.21.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.20.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.19.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.17.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.