@floating-ui/react
Floating UI for React
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): @floating-ui/utils is a first-party package from the same floating-ui monorepo/publisher; adding it is an expected refactor, not a supply-chain risk. | ai | |
| dependencies | unvetted-peer-dep:react-dom | AI (dependencies): react-dom is a standard peer dependency for React libraries; unvetted peer dep status is expected and acceptable. | ai | |
| provenance | missing-githead | AI (provenance): atomiks is a long-standing trusted publisher with 440 approved packages; missing gitHead reflects a publish environment change, not a supply chain compromise signal for this package. | ai | |
| provenance | no-provenance | AI (provenance): Lack of Sigstore provenance is a process gap, not a security indicator, for this well-established package from a trusted publisher. | ai | |
| dependencies | unvetted-dep:@floating-ui/react-dom | AI (dependencies): @floating-ui/react-dom is a sibling package in the same ecosystem; unvetted status is expected and acceptable for this package. | ai |
Versions (showing 51 of 83)
| Version | Deps | Published |
|---|---|---|
| 0.27.19 | 3 / 18 | |
| 0.27.18 | 3 / 18 | |
| 0.27.17 | 3 / 18 | |
| 0.27.16 | 3 / 18 | |
| 0.27.15 | 3 / 18 | |
| 0.27.14 | 3 / 18 | |
| 0.27.13 | 3 / 18 | |
| 0.27.12 | 3 / 18 | |
| 0.27.11 | 3 / 18 | |
| 0.27.10 | 3 / 18 | |
| 0.27.9 | 3 / 18 | |
| 0.27.8 | 3 / 17 | |
| 0.27.7 | 3 / 17 | |
| 0.27.6 | 3 / 17 | |
| 0.27.5 | 3 / 17 | |
| 0.27.4 | 3 / 17 | |
| 0.27.3 | 3 / 17 | |
| 0.27.2 | 3 / 17 | |
| 0.27.1 | 3 / 17 | |
| 0.27.0 | 3 / 17 | |
| 0.26.28 | 3 / 17 | |
| 0.26.27 | 3 / 17 | |
| 0.26.26 | 3 / 17 | |
| 0.26.25 | 3 / 17 | |
| 0.26.24 | 3 / 17 | |
| 0.26.23 | 3 / 17 | |
| 0.26.22 | 3 / 17 | |
| 0.26.21 | 3 / 17 | |
| 0.26.20 | 3 / 17 | |
| 0.26.19 | 3 / 17 | |
| 0.26.18 | 3 / 17 | |
| 0.26.17 | 3 / 17 | |
| 0.26.16 | 3 / 17 | |
| 0.26.15 | 3 / 17 | |
| 0.26.14 | 3 / 17 | |
| 0.26.13 | 3 / 17 | |
| 0.26.12 | 3 / 17 | |
| 0.26.11 | 3 / 17 | |
| 0.26.10 | 3 / 17 | |
| 0.26.9 | 3 / 17 | |
| 0.26.8 | 3 / 17 | |
| 0.26.7 | 3 / 17 | |
| 0.26.6 | 3 / 17 | |
| 0.26.5 | 3 / 17 | |
| 0.26.4 | 3 / 16 | |
| 0.26.3 | 3 / 16 | |
| 0.26.2 | 3 / 16 | |
| 0.26.1 | 3 / 16 | |
| 0.26.0 | 3 / 16 | |
| 0.25.4 | 3 / 16 | |
| 0.25.3 | 3 / 16 |
v0.27.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.27.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.27.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.27.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.27.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.27.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.26.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.26.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.26.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.26.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.26.12
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atomiks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.11
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atomiks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.10
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atomiks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.9
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atomiks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.8
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atomiks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atomiks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atomiks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atomiks.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.