← Home

radix-ui

25
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

chancestricklandmark-workos

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New deps are all first-party @radix-ui/* modules. ai
provenance missing-githead AI (provenance): Build-env metadata change; no behavioral risk for this canonical package. ai
publish-pattern dormant-publish AI (publish-pattern): Mature UI library with periodic release cadence; dormancy is normal for this package. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance; stable for this package. ai
npm-metadata no-description AI (npm-metadata): Umbrella re-export package; missing description is cosmetic, not suspicious. ai
dependencies unvetted-dep:@radix-ui/react-select AI (dependencies): Official @radix-ui sub-package from the canonical Radix UI primitives monorepo. ai
dependencies unvetted-dep:@radix-ui/react-tooltip AI (dependencies): Official @radix-ui sub-package from the canonical Radix UI primitives monorepo. ai
dependencies unvetted-dep:@radix-ui/react-dropdown-menu AI (dependencies): Official @radix-ui sub-package from the canonical Radix UI primitives monorepo. ai
dependencies unvetted-dep:@radix-ui/react-hover-card AI (dependencies): Official @radix-ui sub-package from the canonical Radix UI primitives monorepo. ai
dependencies unvetted-dep:@radix-ui/react-menu AI (dependencies): Official @radix-ui sub-package from the canonical Radix UI primitives monorepo. ai
dependencies unvetted-dep:@radix-ui/react-avatar AI (dependencies): Official @radix-ui sub-package from the canonical Radix UI primitives monorepo. ai
dependencies unvetted-dep:@radix-ui/react-dialog AI (dependencies): Official @radix-ui sub-package from the canonical Radix UI primitives monorepo. ai
dependencies unvetted-dep:@radix-ui/react-popper AI (dependencies): Official @radix-ui sub-package from the canonical Radix UI primitives monorepo. ai
provenance no-provenance AI (provenance): Established official Radix UI package; lack of Sigstore provenance is common and not a risk signal here. ai

Versions (showing 25 of 25)

Version Deps Published
1.6.7 55 / 7
1.6.6 55 / 7
1.6.5 55 / 7
1.6.4 55 / 7
1.6.3 55 / 7
1.6.2 55 / 7
1.6.1 55 / 7
1.6.0 55 / 7
1.5.0 55 / 7
1.4.3 55 / 9
1.4.2 55 / 9
1.4.1 55 / 9
1.4.0 55 / 9
1.3.4 54 / 9
1.3.3 54 / 9
1.3.2 54 / 9
1.3.1 54 / 9
1.3.0 54 / 9
1.2.0 50 / 8
1.1.3 50 / 8
1.1.2 50 / 6
1.1.1 49 / 6
1.1.0 49 / 6
1.0.1 31 / 0
1.0.0 31 / 0

v1.6.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.5

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: chancestrickland → GitHub Actions (on 2026-07-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (chancestrickland) on 2026-07-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.6.4

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.

INFO Publisher changed: GitHub Actions → chancestrickland (on 2026-07-20, known maintainer) provenance

This version was published by a different npm account (chancestrickland) than the most recent previously approved version (GitHub Actions) on 2026-07-20, but chancestrickland is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.4

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.3

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.2

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.1

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.