@xsolla/xui-b2b-collapsible
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Internal scoped component library; sparse metadata is consistent across the @xsolla org's packages. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Org-internal component package; missing description is a style issue, not a risk indicator here. | ai | |
| provenance | no-provenance | AI (provenance): No provenance is common; no other risk signals present to elevate this. | ai | |
| phantom-deps | phantom-dep:@xsolla/xui-primitives-core | AI (phantom-deps): Same-org monorepo dep declared at matching version; phantom-dep heuristic fires on build artifacts that may not directly import it. | ai |
Versions (showing 37 of 37)
| Version | Deps | Published |
|---|---|---|
| 0.170.0 | 3 / 8 | |
| 0.169.0 | 3 / 8 | |
| 0.168.1 | 3 / 8 | |
| 0.168.0 | 3 / 8 | |
| 0.167.0 | 3 / 8 | |
| 0.166.0 | 3 / 8 | |
| 0.165.0 | 3 / 8 | |
| 0.164.0 | 3 / 8 | |
| 0.163.0 | 3 / 8 | |
| 0.162.0 | 3 / 8 | |
| 0.161.3 | 3 / 8 | |
| 0.161.2 | 3 / 8 | |
| 0.161.1 | 3 / 8 | |
| 0.161.0 | 3 / 8 | |
| 0.160.2 | 3 / 8 | |
| 0.160.1 | 3 / 8 | |
| 0.160.0 | 3 / 8 | |
| 0.159.0 | 3 / 8 | |
| 0.158.0 | 3 / 8 | |
| 0.157.0 | 3 / 8 | |
| 0.156.0 | 3 / 8 | |
| 0.155.0 | 3 / 8 | |
| 0.154.2 | 3 / 8 | |
| 0.154.1 | 3 / 8 | |
| 0.154.0 | 3 / 8 | |
| 0.153.2 | 3 / 8 | |
| 0.153.1 | 3 / 8 | |
| 0.153.0 | 3 / 8 | |
| 0.152.0 | 3 / 8 | |
| 0.151.0 | 3 / 8 | |
| 0.150.0 | 3 / 8 | |
| 0.149.1 | 3 / 8 | |
| 0.149.0 | 3 / 8 | |
| 0.148.2 | 3 / 8 | |
| 0.148.1 | 3 / 8 | |
| 0.148.0 | 3 / 8 | |
| 0.147.1 | 3 / 8 |
v0.170.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.169.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.168.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.168.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.167.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.166.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.165.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.164.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.163.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.162.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.161.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.161.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.161.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.161.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.160.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.160.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.160.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.159.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.158.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.157.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.156.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.155.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.154.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.154.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.154.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.153.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.153.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.153.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.152.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.151.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.150.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.149.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.149.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.148.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.148.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.148.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.147.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.