rc-calendar
React Calendar
17
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
afc163benjycuiparanoidjkyesmeckyiminghe
Keywords
reactreact-calendarreact-componentcalendarui componentuicomponent
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher change from afc163 to zombiej in Jan 2019 is a documented maintainer transition within the react-component org. zombiej is a prolific, established publisher in this ecosystem. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): react-lifecycles-compat is a React core team utility for React 16.3+ lifecycle compatibility. Its addition alongside removal of create-react-class is a standard migration pattern, not a supply chain risk. | ai |