← Home

umi

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sorryccstormslowlyyutingzhao1991popomorepeachscriptchenshuai2144yifankakaxixusd320zoomdong07

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Established package; provenance attestation is a best-practice signal, not a blocker. ai
dependencies unvetted-dep:@umijs/core AI (dependencies): Internal monorepo sub-package pinned to same version; expected pattern for umi releases. ai
dependencies unvetted-dep:@umijs/bundler-utils AI (dependencies): Internal monorepo sub-package pinned to same version; expected pattern for umi releases. ai
dependencies unvetted-dep:@umijs/utils AI (dependencies): Internal monorepo sub-package pinned to same version; expected pattern for umi releases. ai
publish-pattern dormant-publish AI (publish-pattern): Umi is an active monorepo; version gaps are common between major release cycles for this established package. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): umi is a well-known React framework brand, not a typo of uuid. ai
bogus-package bogus-package AI (bogus-package): Sparse metadata is typical for monorepo sub-packages; umi is a legitimate established framework. ai
phantom-deps phantom-dep:@umijs/renderer-react AI (phantom-deps): @umijs/renderer-react is a runtime dep used indirectly via config; stable false positive for this monorepo package. ai
typosquat typosquat.levenshtein:joi AI (typosquat): umi is a well-known React framework brand, not a typo of joi. ai

Versions (showing 51 of 252)

View all versions
Version Deps Published
4.6.82 11 / 1
4.6.81 11 / 1
4.6.80 11 / 1
4.6.79 11 / 1
4.6.78 11 / 1
4.6.77 11 / 1
4.6.76 11 / 1
4.6.75 11 / 1
4.6.74 11 / 1
4.6.73 11 / 1
4.6.72 11 / 1
4.6.71 11 / 1
4.6.70 11 / 1
4.6.69 11 / 1
4.6.68 11 / 1
4.6.67 11 / 1
4.6.66 12 / 0
4.6.65 12 / 0
4.6.64 12 / 0
4.6.63 12 / 0
4.6.62 12 / 0
4.6.61 12 / 0
4.6.59 12 / 0
4.6.58 12 / 0
4.6.57 12 / 0
4.6.56 12 / 0
4.6.55 12 / 0
4.6.54 12 / 0
4.6.53 12 / 0
4.6.52 12 / 0
4.6.51 12 / 0
4.6.50 12 / 0
4.6.49 12 / 0
4.6.48 12 / 0
4.6.47 12 / 0
4.6.46 12 / 0
4.6.45 12 / 0
4.6.44 12 / 0
4.6.43 12 / 0
4.6.42 12 / 0
4.6.41 12 / 0
4.6.40 12 / 0
4.6.39 12 / 0
4.6.38 12 / 0
4.6.37 12 / 0
4.6.36 12 / 0
4.6.35 12 / 0
4.6.34 12 / 0
4.6.33 12 / 0
4.6.32 12 / 0
4.6.31 12 / 0

v4.6.82

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.81

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.80

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.79

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.78

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.77

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.76

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.75

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.74

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.73

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.72

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.71

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.70

2 findings
HIGH Publisher changed: zoomdong07 → GitHub Actions (on 2026-07-03) provenance

This version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.69

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.