@trackunit/react-components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@trackunit/react-test-setup | AI (phantom-deps): Test setup dependency; common pattern in component libraries, stable for this package. | ai | |
| dependencies | unvetted-dep:@trackunit/react-table-pagination | AI (dependencies): First-party @trackunit sibling package; consistent with the rest of the dependency set from the same org. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established org package; README/keyword signals are false positives for a scoped component library. | ai |
Versions (showing 34 of 351)
| Version | Deps | Published |
|---|---|---|
| 1.10.1 | 17 / 0 | |
| 1.10.0 | 17 / 0 | |
| 1.9.57 | 17 / 0 | |
| 1.9.56 | 17 / 0 | |
| 1.9.55 | 17 / 0 | |
| 1.9.54 | 17 / 0 | |
| 1.9.53 | 17 / 0 | |
| 1.9.51 | 17 / 0 | |
| 1.9.50 | 17 / 0 | |
| 1.9.47 | 17 / 0 | |
| 1.9.46 | 17 / 0 | |
| 1.9.44 | 17 / 0 | |
| 1.9.43 | 17 / 0 | |
| 1.9.41 | 17 / 0 | |
| 1.9.40 | 17 / 0 | |
| 1.9.39 | 17 / 0 | |
| 1.9.38 | 17 / 0 | |
| 1.9.37 | 17 / 0 | |
| 1.9.35 | 17 / 0 | |
| 1.9.34 | 17 / 0 | |
| 1.9.33 | 17 / 0 | |
| 1.9.32 | 17 / 0 | |
| 1.9.31 | 17 / 0 | |
| 1.9.29 | 17 / 0 | |
| 1.9.28 | 17 / 0 | |
| 1.9.27 | 17 / 0 | |
| 1.9.26 | 17 / 0 | |
| 1.9.24 | 17 / 0 | |
| 1.9.23 | 17 / 0 | |
| 1.9.21 | 17 / 0 | |
| 1.9.20 | 17 / 0 | |
| 1.5.41 | 17 / 0 | |
| 1.4.161 | 17 / 0 | |
| 1.4.93 | 16 / 0 |
v1.10.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.57
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.56
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.55
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.54
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.53
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.51
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.50
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.47
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.46
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.44
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.161
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.93
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.