@vuu-ui/vuu-popups
VUU popup components - Context Menu, Dialog etc
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Publisher has strong clean track record; no other risk signals; likely CI environment change rather than supply chain issue. | ai | |
| dependencies | unvetted-dep:@salt-ds/styles | AI (dependencies): salt-ds is a well-known JP Morgan open-source design system; stable dependency for this UI package. | ai | |
| dependencies | unvetted-dep:@salt-ds/window | AI (dependencies): Same salt-ds design system scope; low risk for this UI component library. | ai | |
| dependencies | unvetted-dep:@vuu-ui/vuu-layout | AI (dependencies): Same @vuu-ui monorepo scope; sibling package published by same maintainer. | ai | |
| phantom-deps | phantom-dep:@vuu-ui/vuu-layout | AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic fires on transitive/re-exported usage patterns common in monorepos. | ai | |
| phantom-deps | phantom-dep:@vuu-ui/vuu-data-types | AI (phantom-deps): Types-only sibling dep; not directly imported in JS but used for type declarations — stable false positive for this package. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 2.1.8 | 8 / 0 | |
| 2.1.7 | 8 / 0 | |
| 2.1.6 | 8 / 0 | |
| 2.1.5 | 8 / 0 | |
| 2.1.4 | 8 / 0 | |
| 2.1.3 | 8 / 0 | |
| 2.1.2 | 8 / 0 | |
| 2.1.1 | 8 / 0 | |
| 2.1.0 | 8 / 0 | |
| 2.0.0 | 8 / 0 | |
| 1.0.1 | 8 / 0 | |
| 0.13.118 | 8 / 0 | |
| 0.13.116 | 8 / 0 | |
| 0.13.115 | 8 / 0 | |
| 0.13.111 | 8 / 0 | |
| 0.13.110 | 8 / 0 | |
| 0.13.106 | 8 / 0 | |
| 0.13.100 | 8 / 0 | |
| 0.13.97 | 8 / 0 | |
| 0.13.95 | 8 / 0 | |
| 0.13.93 | 8 / 0 | |
| 0.13.91 | 8 / 0 | |
| 0.13.88 | 8 / 0 | |
| 0.13.87 | 8 / 0 | |
| 0.13.86 | 8 / 0 | |
| 0.13.84 | 8 / 0 | |
| 0.13.79 | 8 / 0 | |
| 0.13.77 | 8 / 0 | |
| 0.13.74 | 8 / 0 | |
| 0.13.73 | 8 / 0 | |
| 0.13.72 | 8 / 0 | |
| 0.13.67 | 8 / 0 |
v2.1.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: heswell.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: heswell.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: heswell.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: heswell.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: heswell.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: heswell.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: heswell.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.118
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: heswell.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.116
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.115
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: heswell.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.111
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: heswell.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.110
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.106
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.100
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.97
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.95
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.93
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.91
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.88
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.87
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.86
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.84
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.79
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.77
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.74
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.73
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.72
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.13.67
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.