← Home

umi

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sorryccstormslowlyyutingzhao1991popomorepeachscriptchenshuai2144yifankakaxixusd320zoomdong07

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Established package; provenance attestation is a best-practice signal, not a blocker. ai
dependencies unvetted-dep:@umijs/core AI (dependencies): Internal monorepo sub-package pinned to same version; expected pattern for umi releases. ai
dependencies unvetted-dep:@umijs/bundler-utils AI (dependencies): Internal monorepo sub-package pinned to same version; expected pattern for umi releases. ai
dependencies unvetted-dep:@umijs/utils AI (dependencies): Internal monorepo sub-package pinned to same version; expected pattern for umi releases. ai
publish-pattern dormant-publish AI (publish-pattern): Umi is an active monorepo; version gaps are common between major release cycles for this established package. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): umi is a well-known React framework brand, not a typo of uuid. ai
bogus-package bogus-package AI (bogus-package): Sparse metadata is typical for monorepo sub-packages; umi is a legitimate established framework. ai
phantom-deps phantom-dep:@umijs/renderer-react AI (phantom-deps): @umijs/renderer-react is a runtime dep used indirectly via config; stable false positive for this monorepo package. ai
typosquat typosquat.levenshtein:joi AI (typosquat): umi is a well-known React framework brand, not a typo of joi. ai

Versions (showing 100 of 252)

Version Deps Published
4.6.82 11 / 1
4.6.81 11 / 1
4.6.80 11 / 1
4.6.79 11 / 1
4.6.78 11 / 1
4.6.77 11 / 1
4.6.76 11 / 1
4.6.75 11 / 1
4.6.74 11 / 1
4.6.73 11 / 1
4.6.72 11 / 1
4.6.71 11 / 1
4.6.70 11 / 1
4.6.69 11 / 1
4.6.68 11 / 1
4.6.67 11 / 1
4.6.66 12 / 0
4.6.65 12 / 0
4.6.64 12 / 0
4.6.63 12 / 0
4.6.62 12 / 0
4.6.61 12 / 0
4.6.59 12 / 0
4.6.58 12 / 0
4.6.57 12 / 0
4.6.56 12 / 0
4.6.55 12 / 0
4.6.54 12 / 0
4.6.53 12 / 0
4.6.52 12 / 0
4.6.51 12 / 0
4.6.50 12 / 0
4.6.49 12 / 0
4.6.48 12 / 0
4.6.47 12 / 0
4.6.46 12 / 0
4.6.45 12 / 0
4.6.44 12 / 0
4.6.43 12 / 0
4.6.42 12 / 0
4.6.41 12 / 0
4.6.40 12 / 0
4.6.39 12 / 0
4.6.38 12 / 0
4.6.37 12 / 0
4.6.36 12 / 0
4.6.35 12 / 0
4.6.34 12 / 0
4.6.33 12 / 0
4.6.32 12 / 0
4.6.31 12 / 0
4.6.30 12 / 0
4.6.29 12 / 0
4.6.28 12 / 0
4.6.27 12 / 0
4.6.26 12 / 0
4.6.25 12 / 0
4.6.24 12 / 0
4.6.23 12 / 0
4.6.22 12 / 0
4.6.21 12 / 0
4.6.20 12 / 0
4.6.19 12 / 0
4.6.18 12 / 0
4.6.17 12 / 0
4.6.16 12 / 0
4.6.15 12 / 0
4.6.14 12 / 0
4.6.13 12 / 0
4.6.12 12 / 0
4.6.11 12 / 0
4.6.10 12 / 0
4.6.9 12 / 0
4.6.8 12 / 0
4.6.7 12 / 0
4.6.6 12 / 0
4.6.5 12 / 0
4.6.4 12 / 0
4.6.3 12 / 0
4.6.2 12 / 0
4.6.1 12 / 0
4.6.0 12 / 0
4.5.3 12 / 0
4.5.2 12 / 0
4.5.1 12 / 0
4.5.0 12 / 0
4.4.12 12 / 0
4.4.11 12 / 0
4.4.10 12 / 0
4.4.9 12 / 0
4.4.8 12 / 0
4.4.7 12 / 0
4.4.6 12 / 0
4.4.5 12 / 0
4.4.4 12 / 0
4.4.3 12 / 0
4.4.2 12 / 0
4.4.1 12 / 0
4.4.0 12 / 0
4.3.36 12 / 0
Showing 100 of 252 Next page →

v4.6.82

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.81

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.80

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.79

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.78

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.77

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.76

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.75

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.74

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.73

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.72

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.71

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.70

2 findings
HIGH Publisher changed: zoomdong07 → GitHub Actions (on 2026-07-03) provenance

This version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.69

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.3.36

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.