@xsolla/xui-b2b-collapsible
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Internal scoped component library; sparse metadata is consistent across the @xsolla org's packages. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Org-internal component package; missing description is a style issue, not a risk indicator here. | ai | |
| provenance | no-provenance | AI (provenance): No provenance is common; no other risk signals present to elevate this. | ai | |
| phantom-deps | phantom-dep:@xsolla/xui-primitives-core | AI (phantom-deps): Same-org monorepo dep declared at matching version; phantom-dep heuristic fires on build artifacts that may not directly import it. | ai |
Versions (showing 51 of 91)
| Version | Deps | Published |
|---|---|---|
| 0.189.2 | 3 / 8 | |
| 0.189.1 | 3 / 8 | |
| 0.189.0 | 3 / 8 | |
| 0.188.4 | 3 / 8 | |
| 0.188.3 | 3 / 8 | |
| 0.188.2 | 3 / 8 | |
| 0.188.1 | 3 / 8 | |
| 0.188.0 | 3 / 8 | |
| 0.187.3 | 3 / 8 | |
| 0.187.2 | 3 / 8 | |
| 0.187.1 | 3 / 8 | |
| 0.187.0 | 3 / 8 | |
| 0.186.3 | 3 / 8 | |
| 0.186.2 | 3 / 8 | |
| 0.186.1 | 3 / 8 | |
| 0.186.0 | 3 / 8 | |
| 0.185.6 | 3 / 8 | |
| 0.185.5 | 3 / 8 | |
| 0.185.4 | 3 / 8 | |
| 0.185.3 | 3 / 8 | |
| 0.185.2 | 3 / 8 | |
| 0.185.1 | 3 / 8 | |
| 0.185.0 | 3 / 8 | |
| 0.184.0 | 3 / 8 | |
| 0.183.0 | 3 / 8 | |
| 0.182.0 | 3 / 8 | |
| 0.181.0 | 3 / 8 | |
| 0.180.0 | 3 / 8 | |
| 0.179.0 | 3 / 8 | |
| 0.178.0 | 3 / 8 | |
| 0.177.0 | 3 / 8 | |
| 0.176.1 | 3 / 8 | |
| 0.176.0 | 3 / 8 | |
| 0.175.0 | 3 / 8 | |
| 0.174.3 | 3 / 8 | |
| 0.174.2 | 3 / 8 | |
| 0.174.1 | 3 / 8 | |
| 0.174.0 | 3 / 8 | |
| 0.173.2 | 3 / 8 | |
| 0.173.1 | 3 / 8 | |
| 0.173.0 | 3 / 8 | |
| 0.172.2 | 3 / 8 | |
| 0.172.1 | 3 / 8 | |
| 0.172.0 | 3 / 8 | |
| 0.171.3 | 3 / 8 | |
| 0.171.2 | 3 / 8 | |
| 0.171.1 | 3 / 8 | |
| 0.171.0 | 3 / 8 | |
| 0.170.6 | 3 / 8 | |
| 0.170.5 | 3 / 8 | |
| 0.170.4 | 3 / 8 |
v0.189.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.189.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.189.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.188.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.188.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.188.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.188.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.188.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.187.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.187.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.187.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.187.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.186.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.186.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.186.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.186.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.185.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.185.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.185.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.185.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.185.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.185.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.185.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.184.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.183.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.182.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.181.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.180.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.179.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.178.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.177.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.176.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.176.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.175.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.