@reach/utils
Internal, shared utilities for Reach UI.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/warning | AI (phantom-deps): @types/warning is a type declaration package, not a runtime import. Phantom-dep finding is a known false positive for @types/* packages. | ai | |
| source-diff | net-exec-file:dist/reach-utils.cjs.dev.js | AI (source-diff): Standard Rollup CJS bundle for a React utility library. 'Network' signal is from JSDoc URL comments; 'exec' signal is from standard interop helpers. No actual network calls or dynamic code execution. | ai | |
| source-diff | net-exec-file:dist/reach-utils.cjs.prod.js | AI (source-diff): Standard Rollup CJS production bundle. Same false-positive pattern as dev bundle — JSDoc URLs and interop boilerplate, not malware. | ai | |
| source-diff | net-exec-file:dist/reach-utils.esm.js | AI (source-diff): Standard Rollup ESM bundle. Same false-positive pattern — JSDoc URLs and module interop patterns, not actual network or exec activity. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard TypeScript runtime helper; phantom-dep finding is expected for this type of package. | ai | |
| provenance | missing-githead | AI (provenance): Missing gitHead reflects a CI/CD environment change for this well-established package; no security implication given clean package contents and trusted publisher. | ai | |
| provenance | no-provenance | AI (provenance): Informational only; many established packages lack Sigstore provenance. Not a security risk for this well-known package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): chancestrickland is the legitimate Reach UI maintainer with 1797 approved packages. Internal utility package naturally has sparse README and no keywords. | ai | |
| provenance | publisher-changed | AI (provenance): ryanflorence and mjackson are co-maintainers of Reach UI; this transition is a known, legitimate handoff between collaborators on the same project. | ai | |
| email-domain | unclaimed-email:ryanflorence | AI (email-domain): The author field uses '@ryanflorence' as a Twitter-handle placeholder, not a real email address. No actual email domain is at risk of hijacking. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): mjackson is Michael Jackson, co-author of Reach UI alongside Ryan Florence. Addition is a legitimate, expected co-maintainer transition. | ai |
Versions (showing 45 of 45)
| Version | Deps | Published |
|---|---|---|
| 0.18.0 | 0 / 6 | |
| 0.17.0 | 2 / 2 | |
| 0.16.0 | 2 / 2 | |
| 0.15.3 | 2 / 2 | |
| 0.15.2 | 2 / 2 | |
| 0.15.0 | 2 / 2 | |
| 0.14.0 | 3 / 2 | |
| 0.13.2 | 3 / 2 | |
| 0.13.1 | 3 / 2 | |
| 0.13.0 | 3 / 0 | |
| 0.12.1 | 3 / 0 | |
| 0.12.0 | 3 / 0 | |
| 0.11.2 | 3 / 0 | |
| 0.11.1 | 3 / 0 | |
| 0.11.0 | 3 / 0 | |
| 0.10.5 | 3 / 0 | |
| 0.10.4 | 3 / 0 | |
| 0.10.3 | 3 / 0 | |
| 0.10.2 | 3 / 0 | |
| 0.10.1 | 3 / 0 | |
| 0.10.0 | 2 / 0 | |
| 0.9.0 | 2 / 0 | |
| 0.8.6 | 2 / 0 | |
| 0.8.5 | 2 / 0 | |
| 0.8.4 | 2 / 0 | |
| 0.8.3 | 2 / 0 | |
| 0.8.2 | 2 / 0 | |
| 0.8.0 | 0 / 0 | |
| 0.7.4 | 0 / 0 | |
| 0.7.3 | 0 / 0 | |
| 0.7.2 | 0 / 0 | |
| 0.7.1 | 0 / 0 | |
| 0.7.0 | 0 / 0 | |
| 0.6.4 | 0 / 0 | |
| 0.6.1 | 0 / 0 | |
| 0.5.0 | 0 / 0 | |
| 0.4.0 | 0 / 0 | |
| 0.3.0 | 0 / 0 | |
| 0.2.3 | 0 / 0 | |
| 0.2.2 | 0 / 0 | |
| 0.2.1 | 0 / 0 | |
| 0.2.0 | 0 / 0 | |
| 0.1.2 | 0 / 0 | |
| 0.1.1 | 0 / 0 | |
| 0.1.0 | 0 / 0 |
v0.18.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.3
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2021-07-10. This could indicate a legitimate maintainer transition or an account compromise.
v0.15.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.1
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2020-11-27. This could indicate a legitimate maintainer transition or an account compromise.
v0.12.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2020-11-26. This could indicate a legitimate maintainer transition or an account compromise.
v0.11.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.2
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2020-01-10. This could indicate a legitimate maintainer transition or an account compromise.
v0.7.1
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chancestrickland.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2020-01-08. This could indicate a legitimate maintainer transition or an account compromise.
v0.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
3 findingsThis version was published by a different npm account than previous versions on 2019-10-11. This could indicate a legitimate maintainer transition or an account compromise.
Maintainer email '@ryanflorence' uses domain 'ryanflorence' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.