@ladle/react
3
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
miksuladle-ci
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): SLSA provenance attestation confirms CI/CD publish; dormancy explained by major version gap (v2→v5). | ai | |
| phantom-deps | phantom-dep:@vitejs/plugin-react | AI (phantom-deps): Declared runtime dep used via config files; phantom-dep heuristic is a false positive. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Used to deserialize user-controlled storyOrder config string; dev-tool pattern, not exfiltration. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped Babel dep loaded by convention in this build tool. | ai | |
| phantom-deps | phantom-dep:cross-spawn | AI (phantom-deps): CLI tool dep referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped Babel dep; stable false positive for this build tool. | ai | |
| phantom-deps | phantom-dep:@babel/preset-env | AI (phantom-deps): Framework-scoped Babel preset; stable false positive for this build tool. | ai | |
| phantom-deps | phantom-dep:@babel/preset-react | AI (phantom-deps): Framework-scoped Babel preset; stable false positive for this build tool. | ai | |
| phantom-deps | phantom-dep:@babel/preset-typescript | AI (phantom-deps): Framework-scoped Babel preset; stable false positive for this build tool. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-proposal-class-properties | AI (phantom-deps): Framework-scoped Babel plugin; stable false positive for this build tool. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): prop-types is a peer/runtime dep for React components; not directly imported but legitimately declared. | ai |
v5.1.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.5.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.