← Home

@tamagui/static

46
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

nwienert

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:dynamic-require AI (semgrep): Config-loading pattern in a static analysis/compiler tool; stable and expected for this package. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get used in a Proxy handler for theme access tracking; legitimate pattern in this UI toolkit. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package; missing README/description/keywords is normal for internal scoped packages. ai
npm-metadata no-description AI (npm-metadata): Monorepo sub-package; no description is expected. ai
phantom-deps phantom-dep:@tamagui/fake-react-native AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:@tamagui/shorthands AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:@tamagui/helpers-node AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:browserslist AI (phantom-deps): Used in config files; phantom-dep heuristic is a false positive for this build tool. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped; loaded by convention in Babel-based tooling. ai
phantom-deps phantom-dep:react-native-web AI (phantom-deps): Platform-specific dep; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:babel-literal-to-ast AI (phantom-deps): Used in config/build context; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:check-dependency-version-consistency AI (phantom-deps): Build tooling dep; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:@babel/plugin-transform-react-jsx AI (phantom-deps): Loaded by convention in Babel pipeline; phantom-dep heuristic is a false positive. ai

Versions (showing 46 of 46)

Version Deps Published
2.1.0 35 / 12
2.0.0 35 / 12
1.144.4 34 / 13
1.144.3 34 / 13
1.144.2 34 / 13
1.144.1 34 / 13
1.144.0 34 / 13
1.143.1 34 / 13
1.143.0 34 / 13
1.142.0 34 / 13
1.141.5 34 / 13
1.141.4 34 / 13
1.141.3 34 / 13
1.141.2 34 / 13
1.141.1 34 / 13
1.141.0 34 / 13
1.140.4 34 / 13
1.140.3 34 / 13
1.140.2 34 / 13
1.140.1 34 / 13
1.140.0 34 / 13
1.139.4 34 / 13
1.139.3 34 / 13
1.139.2 34 / 13
1.139.1 34 / 13
1.139.0 34 / 13
1.138.6 34 / 13
1.138.5 34 / 13
1.138.4 34 / 13
1.138.3 34 / 13
1.138.2 34 / 13
1.138.1 34 / 13
1.138.0 34 / 13
1.137.3 34 / 13
1.137.2 34 / 13
1.137.1 34 / 13
1.137.0 34 / 13
1.136.9 34 / 13
1.136.8 34 / 13
1.136.7 34 / 13
1.136.6 34 / 13
1.136.4 34 / 13
1.136.3 34 / 13
1.136.2 34 / 13
1.136.1 34 / 13
1.136.0 34 / 13

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.144.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.144.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.144.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.144.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.144.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.143.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.143.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.142.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.141.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.141.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.141.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.141.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.141.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.141.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.140.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.140.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.140.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.140.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.140.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.139.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.139.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.139.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.139.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.139.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.138.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.138.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.138.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.138.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.138.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.138.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.138.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.137.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.137.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.137.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.137.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.136.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.136.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.136.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.136.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.136.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.136.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.136.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.136.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.136.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.