@storybook/ui
Core Storybook UI
44
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
shilmanndelangenhypnosphitmeasdayigor-dv
Keywords
storybook
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:history | AI (phantom-deps): Phantom dependency is legitimate for this package; likely used transitively through @storybook/* dependencies. | ai | |
| phantom-deps | phantom-dep:react-lifecycles-compat | AI (phantom-deps): Phantom dependency is legitimate; used for React compatibility through transitive dependencies. | ai | |
| phantom-deps | phantom-dep:lodash.throttle | AI (phantom-deps): Phantom dependency is legitimate; used in event handling through transitive dependencies. | ai | |
| phantom-deps | phantom-dep:lodash.sortby | AI (phantom-deps): Phantom dependency is legitimate; used in data processing through transitive dependencies. | ai | |
| phantom-deps | phantom-dep:react-modal | AI (phantom-deps): Phantom dependency is legitimate; used in modal UI components through transitive dependencies. | ai | |
| phantom-deps | phantom-dep:keycode | AI (phantom-deps): Phantom dependency is legitimate; used in UI event handling through transitive dependencies. | ai | |
| phantom-deps | phantom-dep:qs | AI (phantom-deps): Declared in package.json; phantom-dep pattern is expected for Storybook monorepo packages. | ai | |
| phantom-deps | phantom-dep:telejson | AI (phantom-deps): Declared in package.json; phantom-dep pattern is expected for Storybook monorepo packages. | ai | |
| phantom-deps | phantom-dep:util-deprecate | AI (phantom-deps): Declared in package.json; phantom-dep pattern is expected for Storybook monorepo packages. | ai | |
| phantom-deps | phantom-dep:emotion-theming | AI (phantom-deps): Declared in package.json; phantom-dep pattern is expected for Storybook monorepo packages. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Declared in package.json; phantom-dep pattern is expected for Storybook monorepo packages. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): @storybook/ui is a scoped package in the official Storybook org; Levenshtein comparison to 'uuid' is a false positive with no plausible confusion. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): @storybook/ui is a scoped package in the official Storybook org; Levenshtein comparison to 'qs' is a false positive with no plausible confusion. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @storybook/ui is a scoped package in the official Storybook org; Levenshtein comparison to 'joi' is a false positive with no plausible confusion. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): @storybook/ui is a scoped package in the official Storybook org; Levenshtein comparison to 'yup' is a false positive with no plausible confusion. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): @storybook/ui is a scoped package in the official Storybook org; Levenshtein comparison to 'pg' is a false positive with no plausible confusion. | ai | |
| phantom-deps | phantom-dep:core-js-pure | AI (phantom-deps): core-js-pure is a declared runtime dep used as part of Storybook's polyfill strategy; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/markdown-to-jsx | AI (phantom-deps): Type definitions declared as runtime dep for framework convention loading; false positive for this package. | ai | |
| phantom-deps | phantom-dep:@storybook/channels | AI (phantom-deps): Same-org Storybook package declared as a runtime dep; phantom detection is a false positive for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@emotion/core | AI (phantom-deps): @emotion/core is a declared dep referenced in config/build files; standard for Storybook's theming/emotion setup. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance support; trusted publisher with strong track record. Not a risk signal for this package. | ai |
Versions (showing 44 of 244)
| Version | Deps | Published |
|---|---|---|
| 3.4.2 | 21 / 2 | |
| 3.4.1 | 21 / 2 | |
| 3.4.0 | 21 / 2 | |
| 3.3.15 | 23 / 2 | |
| 3.3.14 | 23 / 2 | |
| 3.3.13 | 23 / 2 | |
| 3.3.12 | 23 / 2 | |
| 3.3.11 | 23 / 2 | |
| 3.3.10 | 23 / 2 | |
| 3.3.9 | 23 / 2 | |
| 3.3.8 | 23 / 2 | |
| 3.3.7 | 23 / 2 | |
| 3.3.6 | 23 / 2 | |
| 3.3.5 | 23 / 2 | |
| 3.3.4 | 23 / 2 | |
| 3.3.3 | 23 / 2 | |
| 3.3.2 | 21 / 2 | |
| 3.3.1 | 21 / 2 | |
| 3.3.0 | 21 / 2 | |
| 3.2.19 | 23 / 0 | |
| 3.2.18 | 23 / 0 | |
| 3.2.17 | 23 / 0 | |
| 3.2.16 | 23 / 0 | |
| 3.2.15 | 23 / 0 | |
| 3.2.14 | 23 / 0 | |
| 3.2.13 | 23 / 0 | |
| 3.2.12 | 23 / 1 | |
| 3.2.11 | 23 / 1 | |
| 3.2.10 | 23 / 1 | |
| 3.2.7 | 23 / 1 | |
| 3.2.6 | 23 / 1 | |
| 3.2.5 | 22 / 1 | |
| 3.2.4 | 22 / 1 | |
| 3.2.3 | 21 / 1 | |
| 3.2.0 | 21 / 1 | |
| 3.1.9 | 19 / 1 | |
| 3.1.6 | 19 / 1 | |
| 3.1.5 | 19 / 1 | |
| 3.1.3 | 19 / 1 | |
| 3.1.2 | 19 / 1 | |
| 3.1.1 | 19 / 1 | |
| 3.1.0 | 19 / 1 | |
| 3.0.1 | 18 / 0 | |
| 3.0.0 | 18 / 0 |