← Home

@ant-design/cssinjs

Component level cssinjs resolution for antd

65
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

afc163zombiejchenshuai2144arvinxxmadcccranranup123

Keywords

reactcssinjsantdant-design

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): clsx and @rc-component/util are established packages; new deps are legitimate for v2.0.1. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainer addition aligns with publisher change; consistent with Ant Design org transition. ai
dependencies unvetted-dep:@emotion/unitless AI (dependencies): @emotion/unitless is a standard CSS-in-JS utility; unvetted status is expected. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer removal is consistent with legitimate team transitions in established packages. ai
dependencies unvetted-dep:rc-util AI (dependencies): rc-util is a utility library from the React Component ecosystem; appropriate for this package. ai
provenance no-provenance AI (provenance): Package predates Sigstore adoption; not a risk for established ecosystem package. ai
dependencies unvetted-dep:stylis AI (dependencies): stylis is a standard CSS preprocessor library; unvetted status is expected for ecosystem dependencies. ai
phantom-deps phantom-dep:classnames AI (phantom-deps): classnames is declared and referenced in config; not a hidden injection. ai
provenance publisher-changed AI (provenance): Publisher change (madccc → zombiej) aligns with repository consistency; likely legitimate maintainer transition. ai
source-diff large-new-source-files AI (source-diff): 24 new files align with major version bump; no evidence of injected code. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): clsx is declared and used in config; phantom-dep pattern is expected for utility libraries. ai
dependencies unvetted-dep:@rc-component/util AI (dependencies): @rc-component/util is from the rc-component org (Ant Design ecosystem); expected dependency for this package. ai

Versions (showing 65 of 65)

Show 4 prereleases
Version Deps Published
2.1.2 7 / 27
2.1.1 7 / 27
2.1.0 7 / 27
2.0.3 7 / 27
2.0.2 7 / 27
2.0.1 7 / 27
2.0.0 7 / 28
1.24.0 7 / 28
1.23.0 7 / 28
1.22.1 7 / 28
1.22.0 7 / 28
1.21.1 7 / 28
1.21.0 7 / 28
1.20.0 7 / 28
1.19.1 7 / 28
1.19.0 7 / 28
1.18.5 7 / 28
1.18.4 7 / 28
1.18.2 7 / 28
1.18.1 7 / 28
1.18.0 7 / 28
1.17.5 7 / 28
1.17.4 7 / 28
1.17.3 7 / 28
1.17.2 7 / 28
1.17.1 7 / 28
1.17.0 7 / 28
1.16.2 7 / 28
1.16.1 7 / 28
1.16.0 7 / 28
1.15.0 7 / 28
1.14.0 7 / 28
1.13.2 7 / 28
1.13.1 7 / 28
1.13.0 7 / 28
1.12.0 7 / 28
1.11.2 7 / 28
1.11.1 7 / 28
1.11.0 7 / 28
1.10.1 7 / 28
1.10.0 7 / 28
1.9.1 7 / 26
1.9.0 7 / 26
1.8.1 7 / 26
1.7.1 7 / 26
1.7.0 7 / 26
1.6.2 7 / 26
1.6.1 7 / 26
1.6.0 7 / 26
1.5.6 7 / 26
1.5.5 7 / 26
1.5.4 7 / 26
1.5.3 7 / 26
1.5.2 7 / 26
1.5.1 7 / 26
1.5.0 7 / 26
1.4.0 7 / 26
1.3.2 7 / 26
1.3.1 8 / 27
1.3.0 8 / 27
1.2.0 8 / 26
1.1.1 7 / 25
1.1.0 7 / 25
1.0.2 7 / 25
1.0.0 7 / 25