← Home

shadcn

29
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

shadcnnpm_bot_shadcn

Keywords

componentsuitailwindradix-uibase-uishadcn

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:msw AI (phantom-deps): Declared runtime dep, bundled into dist; phantom-dep heuristic is a stable FP for this package. ai
phantom-deps phantom-dep:ora AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:diff AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:open AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:execa AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:kleur AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:dedent AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:recast AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:prompts AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:commander AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:deepmerge AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:fast-glob AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:fuzzysort AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:cosmiconfig AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:browserslist AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai
phantom-deps phantom-dep:@babel/parser AI (phantom-deps): Declared runtime dep, bundled into dist; stable FP. ai

Versions (showing 29 of 29)

Version Deps Published
4.11.0 33 / 10
4.10.0 34 / 9
4.9.0 34 / 9
4.8.3 34 / 9
4.8.2 34 / 9
4.8.1 34 / 9
4.8.0 34 / 9
4.7.0 34 / 9
4.6.0 34 / 9
4.5.0 34 / 9
4.4.0 34 / 9
4.3.1 34 / 9
4.3.0 34 / 9
4.2.0 34 / 9
4.1.2 34 / 9
4.1.1 34 / 9
4.1.0 34 / 9
4.0.8 34 / 9
4.0.4 35 / 8
3.8.2 34 / 8
3.8.1 34 / 8
3.8.0 34 / 8
3.7.0 34 / 8
3.6.3 34 / 8
3.6.2 32 / 8
3.6.1 32 / 8
3.6.0 32 / 8
3.5.2 30 / 8
3.5.1 30 / 8

v4.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.8.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.