← Home

@rjsf/core

A simple React component capable of building HTML forms out of a JSON schema.

20
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

epicfaacerjsf-bot

Keywords

reactformjson-schema

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): rjsf-team migrated publishing to GitHub Actions CI/CD with SLSA provenance attestation; the publisher change from rjsf-bot to GitHub Actions is a legitimate automation transition, not a compromise. ai
phantom-deps phantom-dep:prop-types AI (phantom-deps): prop-types is a declared runtime dependency in package.json for this React library; stable false positive for this package. ai
typosquat typosquat.levenshtein:cors AI (typosquat): @rjsf/core is the legitimate react-jsonschema-form core package; 'core' vs 'cors' is a generic word collision, not impersonation. Stable false positive for this scoped package. ai

Versions (showing 20 of 20)

Version Deps Published
6.6.1 4 / 11
6.6.0 4 / 11
6.5.3 4 / 12
6.5.2 4 / 12
6.5.1 4 / 12
6.5.0 4 / 12
6.4.2 4 / 12
6.4.1 4 / 12
6.4.0 4 / 12
6.3.1 4 / 12
6.3.0 4 / 12
6.2.5 4 / 12
6.2.4 4 / 12
6.2.3 4 / 12
6.1.2 4 / 15
6.1.1 4 / 15
6.1.0 4 / 15
6.0.2 4 / 15
6.0.1 4 / 15
6.0.0 4 / 15

v6.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.