← Home

@lobehub/ui

43
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sudongyueramazing129arvinxxcanisminor1990lobehubbotnekomeowwwrdmclin2blueboylijian

Keywords

lobehubcomponentschatbot componentsreact componentsreact ui

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Established high-download package; provenance absence is consistent across all prior versions. ai
dependencies unvetted-dep:react-layout-kit AI (dependencies): Legitimate layout utility used by this UI library; consistent across versions. ai
dependencies unvetted-dep:@lobehub/fluent-emoji AI (dependencies): First-party @lobehub scoped emoji package; consistent with this library's purpose. ai
phantom-deps phantom-dep:@floating-ui/react AI (phantom-deps): Peer/optional dep pattern common in UI component libraries; stable false positive. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped package @lobehub/ui; Levenshtein match to yup is a false positive. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Large UI library; deps referenced in config/re-exports are expected not to be directly imported in source. ai
phantom-deps phantom-dep:rc-image AI (phantom-deps): Large UI library; config-only reference is expected pattern. ai
phantom-deps phantom-dep:emoji-mart AI (phantom-deps): Large UI library; config-only reference is expected pattern. ai
phantom-deps phantom-dep:query-string AI (phantom-deps): Large UI library; config-only reference is expected pattern. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): Scoped package @lobehub/ui; Levenshtein match to uuid is a false positive. ai
phantom-deps phantom-dep:remark-github AI (phantom-deps): Large UI library; config-only reference is expected pattern. ai
phantom-deps phantom-dep:@ant-design/cssinjs AI (phantom-deps): Large UI library; config-only reference is expected pattern. ai
phantom-deps phantom-dep:@radix-ui/react-slot AI (phantom-deps): Large UI library; config-only reference is expected pattern. ai
phantom-deps phantom-dep:react-zoom-pan-pinch AI (phantom-deps): Large UI library; config-only reference is expected pattern. ai
phantom-deps phantom-dep:@emotion/is-prop-valid AI (phantom-deps): Large UI library; config-only reference is expected pattern. ai
phantom-deps phantom-dep:@mdx-js/react AI (phantom-deps): Large UI library; config-only reference is expected pattern. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped package @lobehub/ui; Levenshtein match to pg is a false positive. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped package @lobehub/ui; Levenshtein match to qs is a false positive. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped package @lobehub/ui; Levenshtein match to joi is a false positive. ai

Versions (showing 43 of 244)

Version Deps Published
3.3.0 65 / 48
3.2.0 65 / 48
3.1.2 65 / 48
3.1.1 65 / 48
3.1.0 65 / 48
3.0.0 65 / 48
2.25.0 65 / 48
2.24.3 65 / 48
2.24.2 65 / 48
2.24.1 65 / 48
2.24.0 65 / 48
2.23.2 65 / 48
2.23.1 65 / 48
2.23.0 65 / 48
2.22.0 65 / 48
2.21.2 65 / 48
2.21.1 65 / 48
2.21.0 65 / 48
2.20.2 65 / 48
2.20.1 65 / 48
2.20.0 65 / 48
2.19.0 65 / 48
2.18.4 65 / 48
2.18.3 65 / 48
2.18.2 65 / 48
2.18.1 65 / 48
2.18.0 65 / 48
2.17.0 65 / 48
2.16.4 65 / 48
2.16.3 65 / 48
2.16.2 65 / 48
2.16.1 65 / 48
2.16.0 65 / 48
2.15.5 65 / 44
2.15.4 63 / 44
2.15.3 63 / 44
2.15.2 63 / 44
2.15.1 63 / 44
2.15.0 63 / 44
2.14.0 63 / 44
2.13.8 63 / 44
2.13.7 63 / 44
2.13.6 63 / 44

v3.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.25.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.24.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.24.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.24.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.24.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.23.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.23.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.23.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.22.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.21.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.21.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.21.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.20.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.20.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.19.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.18.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.18.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.18.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.18.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.18.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.17.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.15.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.15.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.15.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.15.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.15.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.15.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.13.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.13.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.13.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.