react-monaco-editor
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): prop-types is a standard React peer utility, plausibly used in TS/JSX not scanned by heuristic. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase from committed yarn.lock/yarn-error.log files, not code payload. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Long-standing 2018 maintainer handoff, stable for years, not a takeover pattern. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Types-only convention dep, not a real risk. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Peer dep for React component library, not imported directly by design. | ai | |
| phantom-deps | phantom-dep:react-hot-loader | AI (phantom-deps): Dev-tooling peer dep, common false positive for React wrapper libs. | ai |
Versions (showing 51 of 83)
| Version | Deps | Published |
|---|---|---|
| 0.59.0 | 0 / 17 | |
| 0.58.0 | 0 / 17 | |
| 0.57.0 | 1 / 16 | |
| 0.56.2 | 1 / 16 | |
| 0.56.1 | 1 / 16 | |
| 0.56.0 | 1 / 16 | |
| 0.55.0 | 1 / 16 | |
| 0.54.0 | 1 / 16 | |
| 0.53.0 | 1 / 16 | |
| 0.52.0 | 1 / 16 | |
| 0.51.0 | 1 / 16 | |
| 0.50.1 | 1 / 16 | |
| 0.50.0 | 1 / 16 | |
| 0.49.0 | 1 / 16 | |
| 0.48.0 | 1 / 16 | |
| 0.47.0 | 1 / 16 | |
| 0.46.0 | 1 / 16 | |
| 0.45.0 | 2 / 15 | |
| 0.44.0 | 2 / 15 | |
| 0.43.0 | 2 / 15 | |
| 0.42.0 | 2 / 15 | |
| 0.41.2 | 2 / 15 | |
| 0.41.1 | 2 / 15 | |
| 0.41.0 | 2 / 15 | |
| 0.40.0 | 2 / 15 | |
| 0.39.1 | 3 / 13 | |
| 0.39.0 | 3 / 13 | |
| 0.38.0 | 3 / 13 | |
| 0.37.0 | 3 / 18 | |
| 0.36.0 | 3 / 18 | |
| 0.35.0 | 3 / 18 | |
| 0.34.0 | 2 / 19 | |
| 0.33.0 | 2 / 19 | |
| 0.32.1 | 2 / 19 | |
| 0.32.0 | 2 / 19 | |
| 0.31.1 | 2 / 19 | |
| 0.31.0 | 2 / 19 | |
| 0.30.2 | 2 / 19 | |
| 0.30.1 | 2 / 19 | |
| 0.30.0 | 2 / 19 | |
| 0.29.0 | 2 / 19 | |
| 0.28.0 | 2 / 19 | |
| 0.27.0 | 2 / 16 | |
| 0.25.1 | 3 / 16 | |
| 0.25.0 | 3 / 16 | |
| 0.24.1 | 3 / 16 | |
| 0.24.0 | 3 / 16 | |
| 0.23.0 | 3 / 16 | |
| 0.22.0 | 3 / 16 | |
| 0.21.0 | 3 / 16 | |
| 0.20.0 | 3 / 17 |
v0.58.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.56.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.56.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.56.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.55.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2023-12-09. It has since remained available on npm for 956 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.54.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2023-07-26. It has since remained available on npm for 1092 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.53.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2023-06-29. It has since remained available on npm for 1119 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.52.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2023-03-09. It has since remained available on npm for 1231 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.51.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2022-11-22. It has since remained available on npm for 1338 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.50.1
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2022-08-30. It has since remained available on npm for 1422 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.50.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2022-08-30. It has since remained available on npm for 1422 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.49.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2022-06-30. It has since remained available on npm for 1483 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2022-04-25. It has since remained available on npm for 1549 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2022-01-13. It has since remained available on npm for 1651 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.46.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2021-10-26. It has since remained available on npm for 1730 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.45.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2021-09-15. It has since remained available on npm for 1771 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2021-07-27. It has since remained available on npm for 1821 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2021-03-15. It has since remained available on npm for 1955 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2021-02-04. It has since remained available on npm for 1994 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.2
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-12-22. It has since remained available on npm for 2038 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.1
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-12-11. It has since remained available on npm for 2049 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-12-11. It has since remained available on npm for 2049 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.40.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-08-24. It has since remained available on npm for 2158 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.39.1
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-07-13. It has since remained available on npm for 2200 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.39.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-07-11. It has since remained available on npm for 2202 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.38.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-07-11. It has since remained available on npm for 2202 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-07-06. It has since remained available on npm for 2207 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.36.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-04-09. It has since remained available on npm for 2295 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-03-21. It has since remained available on npm for 2314 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-02-12. It has since remained available on npm for 2352 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2020-01-07. It has since remained available on npm for 2388 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.1
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-10-31. It has since remained available on npm for 2456 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-10-31. It has since remained available on npm for 2456 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.1
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-10-22. It has since remained available on npm for 2465 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-09-05. It has since remained available on npm for 2512 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.2
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-09-03. It has since remained available on npm for 2514 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.1
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-08-20. It has since remained available on npm for 2528 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-08-17. It has since remained available on npm for 2531 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-08-13. It has since remained available on npm for 2535 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-07-22. It has since remained available on npm for 2557 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-07-20. It has since remained available on npm for 2559 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.1
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-03-05. It has since remained available on npm for 2696 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-03-05. It has since remained available on npm for 2696 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.1
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-03-02. It has since remained available on npm for 2700 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-02-20. It has since remained available on npm for 2709 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2019-02-04. It has since remained available on npm for 2725 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2018-11-19. It has since remained available on npm for 2802 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.21.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2018-11-13. It has since remained available on npm for 2808 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.20.0
2 findingsThis version was published by a different npm account (domoritz) than the most recent previously approved version (superraytin) on 2018-10-24. It has since remained available on npm for 2828 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.