All rc-cascader versions

rc-cascader @3.6.1

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
34
Risk Score
MIT
License
No
Install Scripts
6
Dependencies
21
Dev Dependencies
22.1 KB
Package Size
Published

cascade select ui component for react

Maintainers

yesmeckafc163ddcat1115zombiejmadccc

Keywords

reactreact-componentreact-cascaderreact-selectselectcascadecascader

Dependencies (6)

PackageConstraintRegistry Status
rc-tree ~5.6.3 auto_approved
rc-util ^5.6.1 auto_approved
rc-select ~14.1.0 auto_approved
classnames ^2.3.1 auto_approved
@babel/runtime ^7.12.5 auto_approved
array-tree-filter ^2.1.0 auto_approved

Dev Dependencies (21)

PackageConstraintRegistry Status
np ^7.6.0 auto_approved
dumi ^1.1.12 needs_review
glob ^7.1.6 auto_approved
react ^16.0.0 auto_approved
enzyme ^3.3.0 auto_approved
father ^2.13.2 rejected
rc-form ^2.4.0 auto_approved
gh-pages ^3.1.0 auto_approved
prettier ^2.7.1 auto_approved
cross-env ^7.0.0 auto_approved
react-dom ^16.0.0 auto_approved
rc-trigger ^5.0.4 auto_approved
typescript ^4.4.2 auto_approved
@types/jest ^27.0.2 pending
@types/react ^17.0.38 auto_approved
@types/enzyme ^3.1.15 Not imported
@types/warning ^3.0.0 auto_approved
enzyme-to-json ^3.2.1 auto_approved
@types/react-dom ^17.0.11 pending
@types/classnames ^2.2.6 pending
enzyme-adapter-react-16 ^1.0.2 auto_approved

Transitive Dependency Tree

16 transitive deps max depth 5
  ├─ @babel/runtime ^7.12.5 → 7.29.2
  ├─ array-tree-filter ^2.1.0
  ├─ classnames ^2.3.1 → 2.5.1
  ├─ rc-select ~14.1.0 → 14.1.18
  ├─ rc-tree ~5.6.3 → 5.6.9
├─ rc-util ^5.6.1 → 5.44.4
  ├─ @babel/runtime ^7.18.3 → 7.29.2
  ├─ @babel/runtime ^7.10.1 → 7.29.2
  ├─ classnames 2.x → 2.5.1
  ├─ rc-motion ^2.0.1 → 2.9.5
  ├─ rc-overflow ^1.0.0 → 1.5.0
  ├─ rc-trigger ^5.0.4 → 5.3.3
  ├─ rc-util ^5.16.1 → 5.44.4
  ├─ rc-virtual-list ^3.4.8 → 3.19.2
  ├─ rc-virtual-list ^3.2.0 → 3.19.2
├─ react-is ^18.2.0 → 18.3.1
  ├─ @babel/runtime ^7.20.0 → 7.29.2
  ├─ @babel/runtime ^7.11.1 → 7.29.2
  ├─ @babel/runtime ^7.18.3 → 7.29.2
  ├─ classnames ^2.2.1 → 2.5.1
  ├─ classnames ^2.2.6 → 2.5.1
  ├─ rc-align ^4.0.0 → 4.0.13
  ├─ rc-motion ^2.0.0 → 2.9.5
  ├─ rc-resize-observer ^1.0.0 → 1.4.3
  ├─ rc-resize-observer ^1.0.0 → 1.4.1
  ├─ rc-util ^5.19.2 → 5.44.4
  ├─ rc-util ^5.36.0 → 5.44.4
  ├─ rc-util ^5.44.0 → 5.44.4
  ├─ rc-util ^5.37.0 → 5.44.4
├─ react-is ^18.2.0 → 18.3.1
  ├─ @babel/runtime ^7.18.3 → 7.29.2
  ├─ @babel/runtime ^7.10.1 → 7.29.2
  ├─ @babel/runtime ^7.20.7 → 7.29.2
  ├─ @babel/runtime ^7.11.1 → 7.29.2
  ├─ classnames ^2.2.1 → 2.5.1
  ├─ classnames 2.x → 2.5.1
  ├─ dom-align ^1.7.0 → 1.12.4
  ├─ lodash ^4.17.21 → 4.18.1
  ├─ rc-util ^5.44.0 → 5.44.4
  ├─ rc-util ^5.3.0 → 5.44.4
  ├─ rc-util ^5.44.1 → 5.44.4
  ├─ react-is ^18.2.0 → 18.3.1
├─ resize-observer-polyfill ^1.5.1 → 1.5.1
  ├─ @babel/runtime ^7.18.3 → 7.29.2
  ├─ react-is ^18.2.0 → 18.3.1

Changes from v3.6.0

No metadata changes detected.

File Changes

5 added 0 removed 7 modified size delta: +5.6 KB

Risk Dispositions (2 applicable to this version, 0 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Rule Source Disposition Author Reason
publisher-changed provenance reject AI AI (provenance): Publisher changed to a SPAM-FLAGGED account (zombiej); this is a disqualifying signal that generalizes across versions published by this account.
bogus-package bogus-package reject AI AI (bogus-package): Multiple maintainers flagged as spam including the current publisher zombiej; spam-flagged publisher is a hard reject signal.

SAST Findings (2)

HIGH Publisher changed: madccc → zombiej (on 2022-06-29) provenance

This version was published by a different npm account than previous versions on 2022-06-29. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

Review Summary

Risk score: 34. Findings: 1 high (+25), 3 low (+9).

Commit: 37db73bb3019 Browse source

Published to npm: