swr
React Hooks library for remote data fetching
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): dequal is a well-known, legitimate deep equality utility by Luke Edwards; its addition to SWR is consistent with the library's functionality and poses no supply chain risk. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): SWR is a Vercel OSS project; large maintainer list reflects Vercel org publishing practices, not a takeover. Stable pattern for this package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removed maintainers are early contributors who moved on; consistent with normal OSS project evolution at Vercel. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects addition of swr/infinite and swr/immutable sub-package bundles introduced in v1.2.0, not injected payloads. | ai | |
| dependencies | unvetted-dep:use-sync-external-store | AI (dependencies): Dependency is already marked as accepted risk; stable for this package. | ai |
Versions (showing 78 of 78)
| Version | Deps | Published |
|---|---|---|
| 2.4.1 | 2 / 40 | |
| 2.4.0 | 2 / 40 | |
| 2.3.8 | 2 / 39 | |
| 2.3.7 | 2 / 39 | |
| 2.3.6 | 2 / 34 | |
| 2.3.5 | 2 / 34 | |
| 2.3.4 | 2 / 34 | |
| 2.3.3 | 2 / 34 | |
| 2.3.2 | 2 / 34 | |
| 2.3.1 | 2 / 34 | |
| 2.3.0 | 2 / 34 | |
| 2.2.5 | 2 / 33 | |
| 2.2.4 | 2 / 33 | |
| 2.2.3 | 2 / 33 | |
| 2.2.2 | 2 / 33 | |
| 2.2.1 | 2 / 33 | |
| 2.2.0 | 1 / 32 | |
| 2.1.5 | 1 / 30 | |
| 2.1.4 | 1 / 30 | |
| 2.1.3 | 1 / 31 | |
| 2.1.2 | 1 / 31 | |
| 2.1.1 | 1 / 31 | |
| 2.1.0 | 1 / 31 | |
| 2.0.4 | 1 / 31 | |
| 2.0.3 | 1 / 31 | |
| 2.0.2 | 1 / 31 | |
| 2.0.1 | 1 / 31 | |
| 2.0.0 | 1 / 30 | |
| 1.3.0 | 0 / 28 | |
| 1.2.2 | 0 / 28 | |
| 1.2.1 | 0 / 28 | |
| 1.2.0 | 0 / 28 | |
| 1.1.2 | 0 / 25 | |
| 1.1.1 | 0 / 25 | |
| 1.1.0 | 0 / 25 | |
| 1.0.1 | 1 / 26 | |
| 1.0.0 | 1 / 26 | |
| 0.5.7 | 1 / 23 | |
| 0.5.6 | 1 / 23 | |
| 0.5.5 | 1 / 23 | |
| 0.5.4 | 0 / 23 | |
| 0.5.3 | 0 / 23 | |
| 0.5.2 | 0 / 23 | |
| 0.5.1 | 0 / 23 | |
| 0.5.0 | 1 / 23 | |
| 0.4.2 | 1 / 19 | |
| 0.4.1 | 1 / 19 | |
| 0.4.0 | 1 / 19 | |
| 0.3.11 | 1 / 19 | |
| 0.3.10 | 1 / 19 | |
| 0.3.9 | 1 / 19 | |
| 0.3.8 | 1 / 19 | |
| 0.3.7 | 1 / 19 | |
| 0.3.6 | 1 / 19 | |
| 0.3.5 | 1 / 19 | |
| 0.3.4 | 1 / 19 | |
| 0.3.3 | 1 / 17 | |
| 0.3.2 | 1 / 17 | |
| 0.3.1 | 1 / 17 | |
| 0.3.0 | 1 / 17 | |
| 0.2.3 | 1 / 17 | |
| 0.2.2 | 1 / 17 | |
| 0.2.1 | 1 / 17 | |
| 0.2.0 | 1 / 17 | |
| 0.1.18 | 1 / 17 | |
| 0.1.17 | 1 / 17 | |
| 0.1.16 | 1 / 17 | |
| 0.1.15 | 1 / 17 | |
| 0.1.14 | 1 / 17 | |
| 0.1.13 | 1 / 17 | |
| 0.1.12 | 1 / 17 | |
| 0.1.10 | 1 / 17 | |
| 0.1.9 | 3 / 18 | |
| 0.1.8 | 3 / 18 | |
| 0.1.7 | 3 / 18 | |
| 0.1.6 | 3 / 18 | |
| 0.1.5 | 3 / 17 | |
| 0.1.2 | 3 / 15 |
v0.5.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.