slate-react
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file-transition:dist/slate-react.min.js | AI (source-diff): Minified build of same UMD bundle; no fetch/exec payload. | ai | |
| source-diff | net-exec-file-transition:dist/slate-react.js | AI (source-diff): Rollup UMD build output; heuristic net+exec match on bundle, no actual dropper behavior. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): slate-dev-warning is a first-party sibling package in the same monorepo. | ai | |
| phantom-deps | phantom-dep:keycode | AI (phantom-deps): Used in transpiled lib/ build output; heuristic misses it due to minification. | ai | |
| source-diff | bulk-obfuscated-files:lib | AI (source-diff): Routine transpiled build output under lib/, not true obfuscation. | ai | |
| phantom-deps | phantom-dep:is-window | AI (phantom-deps): Legitimate small utility dep for DOM checks; likely used but not import-scannable. | ai | |
| phantom-deps | phantom-dep:tiny-invariant | AI (phantom-deps): Declared dependency; used transitively in slate-react codebase. | ai | |
| phantom-deps | phantom-dep:is-plain-object | AI (phantom-deps): Declared dependency; used transitively in slate-react codebase. | ai | |
| phantom-deps | phantom-dep:is-hotkey | AI (phantom-deps): Declared dependency; used transitively in slate-react codebase. | ai |
Versions (showing 51 of 290)
| Version | Deps | Published |
|---|---|---|
| 0.126.0 | 6 / 16 | |
| 0.125.1 | 6 / 16 | |
| 0.124.2 | 6 / 16 | |
| 0.124.0 | 6 / 16 | |
| 0.123.0 | 6 / 16 | |
| 0.120.0 | 6 / 16 | |
| 0.119.0 | 6 / 16 | |
| 0.118.2 | 6 / 16 | |
| 0.117.4 | 6 / 16 | |
| 0.117.3 | 6 / 16 | |
| 0.117.2 | 6 / 16 | |
| 0.117.1 | 6 / 16 | |
| 0.116.0 | 6 / 16 | |
| 0.115.0 | 6 / 15 | |
| 0.114.2 | 7 / 15 | |
| 0.114.0 | 7 / 15 | |
| 0.113.0 | 7 / 15 | |
| 0.112.1 | 7 / 15 | |
| 0.112.0 | 7 / 15 | |
| 0.111.0 | 7 / 15 | |
| 0.110.3 | 7 / 14 | |
| 0.110.2 | 7 / 14 | |
| 0.110.1 | 7 / 14 | |
| 0.110.0 | 7 / 14 | |
| 0.109.0 | 7 / 14 | |
| 0.108.0 | 7 / 14 | |
| 0.107.1 | 9 / 12 | |
| 0.107.0 | 9 / 12 | |
| 0.106.0 | 9 / 12 | |
| 0.105.0 | 9 / 12 | |
| 0.104.0 | 9 / 12 | |
| 0.102.0 | 9 / 12 | |
| 0.101.6 | 9 / 12 | |
| 0.101.5 | 9 / 12 | |
| 0.101.3 | 9 / 12 | |
| 0.101.2 | 9 / 12 | |
| 0.101.1 | 9 / 12 | |
| 0.101.0 | 9 / 12 | |
| 0.100.1 | 9 / 13 | |
| 0.100.0 | 9 / 13 | |
| 0.99.0 | 9 / 13 | |
| 0.98.4 | 9 / 13 | |
| 0.98.3 | 9 / 13 | |
| 0.98.2 | 9 / 13 | |
| 0.98.1 | 9 / 13 | |
| 0.98.0 | 9 / 13 | |
| 0.97.2 | 9 / 13 | |
| 0.97.1 | 9 / 13 | |
| 0.97.0 | 9 / 13 | |
| 0.96.0 | 9 / 13 | |
| 0.95.0 | 9 / 13 |
v0.126.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.125.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.113.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.112.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.112.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.111.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.110.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.110.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.110.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.110.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.109.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.108.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.107.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.107.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.106.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.105.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.104.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.102.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.6
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.5
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.3
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.2
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.101.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.100.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.100.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.99.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.98.4
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.98.3
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.98.2
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.98.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.98.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.97.2
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.97.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.97.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.96.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.95.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.