All rc-tree-select versions

rc-tree-select @5.24.5

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
34
Risk Score
MIT
License
No
Install Scripts
5
Dependencies
31
Dev Dependencies
35.9 KB
Package Size
Published

tree-select ui component for react

Maintainers

yesmeckafc163yiminghewarmhugvalleykidzombiejmadccc

Keywords

reactreact-componentreact-tree-selecttree-select

Dependencies (5)

PackageConstraintRegistry Status
rc-tree ~5.10.1 auto_approved
rc-util ^5.43.0 auto_approved
rc-select ~14.16.2 auto_approved
classnames 2.x auto_approved
@babel/runtime ^7.25.7 auto_approved

Dev Dependencies (31)

PackageConstraintRegistry Status
np ^10.0.7 auto_approved
dumi ^2.4.12 needs_review
glob ^11.0.0 auto_approved
husky ^9.1.6 auto_approved
react ^16.0.0 auto_approved
enzyme ^3.11.0 auto_approved
eslint ^8.57.1 auto_approved
father ^4.5.0 auto_approved
cheerio 1.0.0-rc.12 auto_approved
rc-test ^7.1.1 Not imported
prettier ^3.3.3 auto_approved
cross-env ^7.0.3 auto_approved
rc-dialog ^9.6.0 auto_approved
react-dom ^16.0.0 auto_approved
typescript ^5.6.3 auto_approved
@types/jest ^29.5.13 auto_approved
@types/node ^22.7.5 auto_approved
lint-staged ^15.2.10 auto_approved
@types/react ^18.3.11 auto_approved
@umijs/fabric ^4.0.1 rejected
rc-field-form ^2.4.0 auto_approved
@types/warning ^3.0.3 auto_approved
enzyme-to-json ^3.6.2 auto_approved
rc-virtual-list ^3.14.8 auto_approved
@types/react-dom ^18.3.1 auto_approved
eslint-plugin-jest ^27.9.0 auto_approved
@rc-component/trigger ^1.18.3 auto_approved
eslint-plugin-unicorn ^56.0.0 auto_approved
@testing-library/react ^12.1.5 pending
enzyme-adapter-react-16 ^1.15.8 auto_approved
@rc-component/father-plugin ^1.1.0 Not imported

Transitive Dependency Tree

12 transitive deps max depth 5
  ├─ @babel/runtime ^7.25.7 → 7.29.2
  ├─ classnames 2.x → 2.5.1
  ├─ rc-select ~14.16.2 → 14.16.8
  ├─ rc-tree ~5.10.1 → 5.10.1
├─ rc-util ^5.43.0 → 5.44.4
  ├─ @babel/runtime ^7.10.1 → 7.29.2
  ├─ @babel/runtime ^7.18.3 → 7.29.2
  ├─ @rc-component/trigger ^2.1.1
  ├─ classnames 2.x → 2.5.1
  ├─ rc-motion ^2.0.1 → 2.9.5
  ├─ rc-overflow ^1.3.1 → 1.5.0
  ├─ rc-util ^5.16.1 → 5.44.4
  ├─ rc-virtual-list ^3.5.1 → 3.19.2
  ├─ rc-virtual-list ^3.5.2 → 3.19.2
├─ react-is ^18.2.0 → 18.3.1
  ├─ @babel/runtime ^7.20.0 → 7.29.2
  ├─ @babel/runtime ^7.18.3 → 7.29.2
  ├─ @babel/runtime ^7.11.1 → 7.29.2
  ├─ classnames ^2.2.6 → 2.5.1
  ├─ classnames ^2.2.1 → 2.5.1
  ├─ rc-resize-observer ^1.0.0 → 1.4.3
  ├─ rc-resize-observer ^1.0.0 → 1.4.1
  ├─ rc-util ^5.44.0 → 5.44.4
  ├─ rc-util ^5.37.0 → 5.44.4
  ├─ rc-util ^5.36.0 → 5.44.4
├─ react-is ^18.2.0 → 18.3.1
  ├─ @babel/runtime ^7.18.3 → 7.29.2
  ├─ @babel/runtime ^7.20.7 → 7.29.2
  ├─ classnames ^2.2.1 → 2.5.1
  ├─ rc-util ^5.44.1 → 5.44.4
  ├─ react-is ^18.2.0 → 18.3.1
├─ resize-observer-polyfill ^1.5.1 → 1.5.1
  ├─ @babel/runtime ^7.18.3 → 7.29.2
  ├─ react-is ^18.2.0 → 18.3.1

Changes from v5.24.3

No metadata changes detected.

File Changes

0 added 0 removed 6 modified size delta: +3.2 KB

Risk Dispositions (2 applicable to this version, 0 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Rule Source Disposition Author Reason
publisher-changed provenance reject AI AI (provenance): Publisher changed to a SPAM-FLAGGED account (zombiej); this is a hard reject signal that generalizes to all versions published by this account.
bogus-package bogus-package reject AI AI (bogus-package): Multiple maintainers including the publishing account (zombiej) are flagged as spam; this signal generalizes across versions published under this maintainer set.

SAST Findings (2)

HIGH Publisher changed: afc163 → zombiej (on 2024-11-21) provenance

This version was published by a different npm account than previous versions on 2024-11-21. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

Review Summary

Risk score: 34. Findings: 1 high (+25), 3 low (+9).

Commit: c3bf3cb017f5 Browse source

Published to npm: