@xyo-network/react-payload-table
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): No content changes vs prior version; consistent with monorepo bulk-publish, not a compromised pipeline. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Coordinated monorepo major-version bump (9.0.0 across sibling packages), not an anomalous solo publish. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Package deprecated as shim redirecting to react-sdk; stub size drop expected. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is first-party @xyo-network/react-sdk consolidation, not third-party. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 10.0.6 | 1 / 61 | |
| 10.0.5 | 5 / 56 | |
| 10.0.4 | 5 / 54 | |
| 10.0.3 | 5 / 66 | |
| 10.0.2 | 5 / 68 | |
| 10.0.0 | 5 / 68 | |
| 9.1.1 | 5 / 68 | |
| 9.1.0 | 5 / 68 | |
| 9.0.6 | 5 / 74 | |
| 9.0.5 | 5 / 74 | |
| 9.0.4 | 5 / 73 | |
| 9.0.2 | 5 / 86 | |
| 9.0.1 | 5 / 89 | |
| 9.0.0 | 5 / 93 | |
| 8.0.1 | 5 / 93 | |
| 8.0.0 | 5 / 91 | |
| 7.5.11 | 5 / 105 | |
| 7.5.8 | 13 / 22 | |
| 7.5.7 | 13 / 22 | |
| 7.5.6 | 13 / 21 | |
| 7.5.5 | 13 / 21 | |
| 7.5.4 | 13 / 21 | |
| 7.5.3 | 12 / 21 | |
| 7.5.2 | 12 / 21 | |
| 7.5.1 | 12 / 21 | |
| 7.5.0 | 12 / 20 | |
| 7.4.2 | 14 / 20 | |
| 7.4.1 | 14 / 20 | |
| 7.4.0 | 14 / 20 |
v10.0.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.0.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.0.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.0.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.0.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.5.11
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: xyo.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2026-04-23, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v7.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.