rc-rate
React Star Rate Component
33
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
benjycuiyesmeckafc163yimingheyutingzhao1991zombiejxrkffggmadccc
Keywords
reactreact-componentreact-raterate
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by TypeScript migration and dual CJS/ESM output (lib + es dirs); no obfuscation or injected payloads. | ai | |
| provenance | publisher-changed | AI (provenance): afc163 is a well-known Ant Design/react-component ecosystem maintainer; transition from yiminghe is a legitimate org-level handoff within react-component GitHub org. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers (benjycui, yesmeck, yutingzhao1991, zombiej) are all known contributors to the Ant Design/react-component ecosystem; legitimate team expansion. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @babel/runtime and rc-util are established, well-known packages in the Ant Design ecosystem; standard additions for a TypeScript/ESM refactor. | ai | |
| provenance | no-provenance | AI (provenance): rc-rate is a long-established package from the react-component org; lack of Sigstore provenance is not a meaningful risk signal for this publisher. | ai | |
| dependencies | unvetted-dep:rc-util | AI (dependencies): rc-util is a standard utility library from the same react-component ecosystem used across all rc-* packages; not a risk. | ai |
Versions (showing 33 of 33)
| Version | Deps | Published |
|---|---|---|
| 2.13.1 | 3 / 22 | |
| 2.13.0 | 3 / 21 | |
| 2.12.0 | 3 / 20 | |
| 2.11.2 | 3 / 20 | |
| 2.11.1 | 3 / 20 | |
| 2.11.0 | 3 / 20 | |
| 2.10.0 | 3 / 20 | |
| 2.9.3 | 3 / 20 | |
| 2.9.2 | 3 / 20 | |
| 2.9.1 | 3 / 16 | |
| 2.9.0 | 3 / 16 | |
| 2.8.2 | 3 / 16 | |
| 2.8.1 | 3 / 16 | |
| 2.8.0 | 3 / 16 | |
| 2.7.0 | 3 / 16 | |
| 2.6.0 | 2 / 15 | |
| 2.5.1 | 4 / 8 | |
| 2.5.0 | 4 / 8 | |
| 2.4.3 | 5 / 8 | |
| 2.4.2 | 4 / 8 | |
| 2.4.1 | 4 / 8 | |
| 2.4.0 | 4 / 8 | |
| 2.3.0 | 4 / 8 | |
| 2.2.0 | 3 / 7 | |
| 2.1.1 | 2 / 5 | |
| 2.1.0 | 1 / 6 | |
| 2.0.1 | 1 / 6 | |
| 2.0.0 | 1 / 6 | |
| 1.1.2 | 0 / 6 | |
| 1.1.1 | 0 / 6 | |
| 1.1.0 | 0 / 6 | |
| 1.0.1 | 0 / 6 | |
| 1.0.0 | 0 / 6 |