← Home

@visactor/react-vchart

The react version of VChart 4.x

34
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

liufangfangvisactorownerxuanhunzamhownchensiji.0517youngwindspurpose233ssfxzlixuefei.1313ray_sunxiaoluohesimaqxile611da730zhouxinyu66888zexian_chen

Keywords

reactchartsvisualizationVChartanimationstorytellingVisActorgraphicsinteraction

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): @visactor/vgrammar-core is a first-party dep in the same org scope; routine internal dependency addition. ai
provenance publisher-changed AI (provenance): Transition from manual (simaq) to GitHub Actions CI/CD publish with SLSA attestation; provenance direction is IMPROVED. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy coincides with migration to CI/CD publishing pipeline; not indicative of takeover given SLSA attestation. ai
source-diff net-exec-file:build/index.min.js AI (source-diff): Minified UMD bundle; same rationale as index.js — standard chart library output. ai
source-diff source-size-tripled AI (source-diff): Size increase explained by bundling new @visactor/vchart-extension dependency into UMD build artifacts. ai
source-diff obfuscated-file:build/index.js AI (source-diff): Standard rollup UMD bundle output; long lines are minified chart library code, not obfuscation. ai
source-diff net-exec-file:build/index.js AI (source-diff): UMD bundle for a charting library legitimately contains network calls (fetch for data) and dynamic code patterns; not dropper behavior. ai
phantom-deps phantom-dep:@visactor/vrender-kits AI (phantom-deps): Same-org dep declared in package.json; phantom-dep heuristic false positive for this package. ai

Versions (showing 34 of 34)

Version Deps Published
2.1.4 6 / 26
2.1.3 6 / 26
2.1.2 6 / 26
2.1.1 6 / 26
2.1.0 6 / 26
2.0.22 6 / 26
2.0.21 6 / 26
2.0.20 6 / 26
2.0.19 6 / 26
2.0.18 6 / 26
2.0.17 6 / 26
2.0.16 6 / 26
2.0.15 6 / 26
2.0.14 6 / 26
2.0.13 6 / 26
2.0.12 6 / 26
2.0.11 6 / 26
2.0.10 6 / 26
2.0.9 6 / 26
2.0.8 6 / 26
2.0.7 6 / 26
2.0.6 6 / 26
2.0.5 6 / 26
2.0.4 6 / 26
2.0.3 6 / 26
2.0.2 6 / 26
2.0.1 6 / 26
2.0.0 6 / 26
1.13.27 6 / 26
1.13.26 6 / 26
1.13.25 6 / 26
1.13.24 6 / 26
1.13.23 6 / 26
1.13.22 6 / 26

v2.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.