@xsolla/xui-markdown
A React component that renders markdown content with consistent, theme-aware styling. Uses `react-markdown` under the hood.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@xsolla/xui-primitives-core | AI (phantom-deps): Same-org sibling declared in dependencies; stable pattern for monorepo packages. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo package; missing repo/homepage/keywords is expected for internal scoped packages. | ai |
Versions (showing 51 of 121)
| Version | Deps | Published |
|---|---|---|
| 0.170.0 | 3 / 5 | |
| 0.169.0 | 3 / 5 | |
| 0.168.1 | 3 / 5 | |
| 0.168.0 | 3 / 5 | |
| 0.167.0 | 3 / 5 | |
| 0.166.0 | 3 / 5 | |
| 0.165.0 | 3 / 5 | |
| 0.164.0 | 3 / 5 | |
| 0.163.0 | 3 / 5 | |
| 0.162.0 | 3 / 5 | |
| 0.161.3 | 3 / 5 | |
| 0.161.2 | 3 / 5 | |
| 0.161.1 | 3 / 5 | |
| 0.161.0 | 3 / 5 | |
| 0.160.2 | 3 / 5 | |
| 0.160.1 | 3 / 5 | |
| 0.160.0 | 3 / 5 | |
| 0.159.0 | 3 / 5 | |
| 0.158.0 | 3 / 5 | |
| 0.157.0 | 3 / 5 | |
| 0.156.0 | 3 / 5 | |
| 0.155.0 | 3 / 5 | |
| 0.154.2 | 3 / 5 | |
| 0.154.1 | 3 / 5 | |
| 0.154.0 | 3 / 5 | |
| 0.153.2 | 3 / 5 | |
| 0.153.1 | 3 / 5 | |
| 0.153.0 | 3 / 5 | |
| 0.152.0 | 3 / 5 | |
| 0.151.0 | 3 / 5 | |
| 0.150.0 | 3 / 5 | |
| 0.149.1 | 3 / 5 | |
| 0.149.0 | 3 / 5 | |
| 0.148.2 | 3 / 5 | |
| 0.148.1 | 3 / 5 | |
| 0.148.0 | 3 / 5 | |
| 0.147.1 | 3 / 5 | |
| 0.141.1 | 3 / 5 | |
| 0.141.0 | 3 / 5 | |
| 0.140.0 | 3 / 5 | |
| 0.139.0 | 3 / 5 | |
| 0.138.5 | 3 / 5 | |
| 0.138.4 | 3 / 5 | |
| 0.138.3 | 3 / 5 | |
| 0.138.2 | 3 / 5 | |
| 0.138.1 | 3 / 5 | |
| 0.138.0 | 3 / 5 | |
| 0.137.0 | 3 / 5 | |
| 0.136.0 | 3 / 5 | |
| 0.135.0 | 3 / 5 | |
| 0.134.0 | 3 / 5 |
v0.170.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.169.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.168.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.168.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.167.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.166.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.165.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.164.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.163.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.162.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.161.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.161.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.161.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.161.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.160.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.160.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.160.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.159.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.158.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.157.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.156.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.155.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.154.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.154.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.154.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.153.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.153.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.153.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.152.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.151.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.150.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.149.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.149.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.148.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.148.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.148.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.147.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.141.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.141.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.140.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.139.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.138.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.138.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.138.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.138.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.138.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.138.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.137.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.136.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.135.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.134.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.