← Home

@umijs/preset-umi

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sorryccchenshuai2144kuitospeachscriptxiaohuoniyifankakaxixierenyuanxusd320zoomdong07

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Provenance adoption is sparse; not a disqualifier for established packages. ai
maintainer-change maintainer-added AI (maintainer-change): zoomdong07 added to a large, active monorepo team; no other compromise signals present. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are within the @umijs ecosystem and @stagewise/toolbar; consistent with normal UmiJS feature additions. ai
publish-pattern dormant-publish AI (publish-pattern): Large UmiJS monorepo with 526 versions; publisher has established track record with 286 approved packages. ai
dependencies unvetted-dep:@umijs/utils AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/bundler-utils AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/bundler-esbuild AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/babel-preset-umi AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/bundler-utoopack AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/ui AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/history AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/did-you-know AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/es-module-parser AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:less-plugin-resolve AI (dependencies): Known build utility; no malware indicators. ai
dependencies unvetted-dep:current-script-polyfill AI (dependencies): Small polyfill; no malware indicators. ai
dependencies unvetted-dep:click-to-react-component AI (dependencies): Known dev-experience utility; no malware indicators. ai
phantom-deps phantom-dep:babel-plugin-react-compiler AI (phantom-deps): Listed as direct dep in package.json; phantom-dep heuristic false positive. ai
dependencies unvetted-dep:@umijs/bundler-mako AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@stagewise/toolbar AI (dependencies): Dev toolbar utility; no malware indicators. ai
dependencies unvetted-dep:@umijs/core AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
dependencies unvetted-dep:@umijs/mfsu AI (dependencies): Sibling monorepo package; expected unvetted dep for this package family. ai
semgrep semgrep:child-process-import AI (semgrep): Fires in compiled/os-locale — a bundled devDep for locale detection; not a runtime attack surface. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package; sparse README/description is expected for internal preset packages. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in compiled vendor bundles (isnumber/queue-microtask); not malicious, standard minified library code. ai
semgrep semgrep:env-bulk-read AI (semgrep): Fires in compiled/body-parser — standard HTTP middleware; env read is benign config pattern. ai

Versions (showing 51 of 188)

View all versions
Version Deps Published
4.6.57 39 / 12
4.6.55 39 / 12
4.6.49 39 / 12
4.6.48 39 / 12
4.6.46 39 / 12
4.6.44 39 / 12
4.6.42 39 / 12
4.6.27 39 / 12
4.6.25 39 / 12
4.6.24 39 / 12
4.6.19 39 / 12
4.6.17 39 / 12
4.6.16 39 / 12
4.6.15 39 / 12
4.6.14 39 / 12
4.6.13 39 / 12
4.6.5 39 / 12
4.6.4 39 / 12
4.6.3 39 / 12
4.6.0 39 / 12
4.5.0 39 / 12
4.4.12 38 / 12
4.4.11 37 / 12
4.4.10 37 / 12
4.4.9 37 / 12
4.4.8 37 / 12
4.4.7 37 / 12
4.4.6 37 / 12
4.4.5 37 / 12
4.4.4 37 / 12
4.4.3 37 / 12
4.4.2 37 / 12
4.4.1 37 / 12
4.4.0 37 / 12
4.3.36 37 / 12
4.3.35 37 / 12
4.3.34 37 / 12
4.3.33 37 / 12
4.3.32 37 / 12
4.3.31 37 / 12
4.3.30 37 / 12
4.3.29 37 / 12
4.3.28 37 / 12
4.3.27 37 / 12
4.3.26 37 / 12
4.3.25 37 / 12
4.3.24 37 / 12
4.3.23 37 / 12
4.3.22 37 / 12
4.3.21 37 / 12
4.3.20 37 / 12

v4.4.10

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: xusd320 → sorrycc (on 2025-04-25, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (xusd320) on 2025-04-25, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.8

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → xusd320 (on 2025-04-21, known maintainer) provenance

This version was published by a different npm account (xusd320) than the most recent previously approved version (sorrycc) on 2025-04-21, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.6

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: xusd320 → sorrycc (on 2025-02-28, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (xusd320) on 2025-02-28, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.4

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → xusd320 (on 2025-01-02, known maintainer) provenance

This version was published by a different npm account (xusd320) than the most recent previously approved version (stormslowly) on 2025-01-02, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.3

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → xusd320 (on 2025-01-02, known maintainer) provenance

This version was published by a different npm account (xusd320) than the most recent previously approved version (sorrycc) on 2025-01-02, but xusd320 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.2

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2024-12-19, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-12-19, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2024-12-16, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2024-12-16, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.36

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → yifankakaxi (on 2024-12-06, known maintainer) provenance

This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-12-06, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.35

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: yifankakaxi → stormslowly (on 2024-11-25, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (yifankakaxi) on 2024-11-25, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.34

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.33

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.32

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2024-11-14, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2024-11-14, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.31

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → yifankakaxi (on 2024-11-07, known maintainer) provenance

This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-11-07, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.30

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.29

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.28

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → peachscript (on 2024-10-25, known maintainer) provenance

This version was published by a different npm account (peachscript) than the most recent previously approved version (stormslowly) on 2024-10-25, but peachscript is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.27

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2024-10-16, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-10-16, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.26

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2024-10-14, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-10-14, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.25

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → sorrycc (on 2024-10-10, known maintainer) provenance

This version was published by a different npm account (sorrycc) than the most recent previously approved version (stormslowly) on 2024-10-10, but sorrycc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.24

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: stormslowly → yifankakaxi (on 2024-09-26, known maintainer) provenance

This version was published by a different npm account (yifankakaxi) than the most recent previously approved version (stormslowly) on 2024-09-26, but yifankakaxi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.23

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.22

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.21

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sorrycc → stormslowly (on 2024-09-23, known maintainer) provenance

This version was published by a different npm account (stormslowly) than the most recent previously approved version (sorrycc) on 2024-09-23, but stormslowly is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.3.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.