← Home

@utrecht/component-library-react

7
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

littlebobbytabl.esyolijnnl-design-system-ci

Keywords

nl-design-system

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@utrecht/form-field-error-message-react AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
publish-pattern dormant-publish AI (publish-pattern): Large monorepo with 518 versions; major-version gaps are expected; SLSA provenance confirms CI/CD publish. ai
dependencies unvetted-dep:@utrecht/card-css AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/card-react AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/listbox-react AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/subscript-css AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/combobox-react AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/focus-ring-css AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/superscript-css AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/data-badge-react AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/action-group-react AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/map-control-button-css AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/vega-visualization-css AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/open-forms-container-css AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/form-field-checkbox-react AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
dependencies unvetted-dep:@utrecht/open-forms-container-react AI (dependencies): Same-org @utrecht/* sub-package; consistent with monorepo structure. ai
phantom-deps phantom-dep:@utrecht/data-badge-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/focus-ring-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/logo-image-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/map-marker-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/pagination-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/search-bar-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/logo-button-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/digid-button-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/top-task-nav-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/top-task-link-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/custom-checkbox-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/alternate-lang-nav-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:@utrecht/map-control-button-css AI (phantom-deps): CSS-only sibling package; stable false positive for this monorepo bundle. ai
phantom-deps phantom-dep:lodash.chunk AI (phantom-deps): Used in Calendar component logic; phantom-dep heuristic misses indirect usage patterns. ai
phantom-deps phantom-dep:@utrecht/card-css AI (phantom-deps): CSS-only sibling package; no direct import needed, re-exported as a bundle dep. ai

Versions (showing 7 of 7)

Version Deps Published
14.0.1 103 / 39
14.0.0 103 / 39
13.0.4 104 / 43
13.0.2 104 / 43
13.0.1 104 / 43
13.0.0 104 / 43
11.0.0 104 / 43

v14.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.