← Home

@trapar-waves/react-antd-pro

A React-based project leveraging Ant Design Pro, TanStack tools, and Rsbuild for efficient enterprise application development

8
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

muromi

Keywords

reactantdant-design-protanstackrsbuildtypescripttailwindcssenterprise

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance and consistent CI/CD publisher mitigate account-takeover concern for this package. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall runs 'husky' only — standard git-hooks setup, no network fetch or arbitrary code. ai
phantom-deps phantom-dep:react-scan AI (phantom-deps): react-scan is a dev/perf tool referenced in config; phantom-dep is a stable false positive for this package. ai
phantom-deps phantom-dep:@ant-design/pro-layout AI (phantom-deps): pro-layout is a peer/config-level dep of pro-components; phantom-dep is a stable false positive here. ai

Versions (showing 8 of 8)

Version Deps Published
1.2.0 14 / 27
1.1.24 14 / 26
1.1.23 14 / 25
1.1.22 14 / 25
1.1.21 14 / 25
1.1.19 14 / 25
1.1.18 14 / 25
1.1.17 14 / 25

v1.1.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.