← Home

@storybook/react-native-ui-common

32
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

dannyhwgongregyannbfshilmanvalentinpalkovicjreinholdtmeasdayndelangenstorybook-bot

Keywords

reactreact-nativestorybook

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Official storybookjs org migrated to GitHub Actions CI publishing with SLSA attestation; not a compromise. ai
provenance missing-githead AI (provenance): CI/CD publish via GitHub Actions with SLSA provenance; gitHead absence is expected in this publish flow. ai
phantom-deps phantom-dep:@nozbe/microfuzz AI (phantom-deps): Declared runtime dep replacing fuse.js; phantom-dep heuristic misfires on this package's import pattern. ai

Versions (showing 32 of 32)

Version Deps Published
10.5.3 6 / 5
10.5.2 6 / 5
10.5.1 6 / 5
10.5.0 6 / 5
10.4.7 6 / 4
10.4.6 6 / 4
10.4.5 6 / 4
10.4.4 6 / 4
10.4.3 6 / 4
10.4.2 6 / 4
10.4.1 6 / 4
10.4.0 6 / 4
10.3.2 6 / 4
10.3.1 6 / 4
10.3.0 6 / 4
10.2.3 6 / 3
10.2.2 6 / 3
10.2.1 6 / 3
10.2.0 6 / 3
10.1.11 6 / 7
10.1.3 6 / 7
10.1.2 6 / 7
10.1.1 6 / 7
10.1.0 6 / 7
10.0.7 6 / 7
10.0.6 6 / 7
10.0.5 6 / 7
10.0.4 6 / 7
10.0.3 6 / 7
10.0.2 6 / 7
10.0.1 6 / 7
10.0.0 8 / 7

v10.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v10.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v10.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v10.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.