@alfalab/core-components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is a first-party sibling package in the same @alfalab/core-components-* namespace; not a supply-chain risk. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-text | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-vars | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-space | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-status | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-divider | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-collapse | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-dropzone | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-underlay | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-grid | AI (dependencies): Sibling monorepo package from same org; stable false positive for this umbrella package. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-global-store | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-generic-wrapper | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-segmented-control | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-hatching-progress-bar | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai | |
| dependencies | unvetted-peer-dep:@alfalab/core-components-config | AI (dependencies): Sibling monorepo peer dep from same org; stable false positive. | ai | |
| dependencies | unvetted-peer-dep:@alfalab/core-components-stack-context | AI (dependencies): Sibling monorepo peer dep from same org; stable false positive. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Umbrella package aggregating many sibling components; large file counts are expected on version bumps. | ai | |
| dependencies | unvetted-dep:@alfalab/core-components-card-image | AI (dependencies): Sibling monorepo package from same org; stable false positive. | ai |
Versions (showing 20 of 20)
| Version | Deps | Published |
|---|---|---|
| 50.16.0 | 122 / 0 | |
| 50.15.0 | 122 / 0 | |
| 50.13.0 | 121 / 0 | |
| 50.12.1 | 121 / 0 | |
| 50.11.0 | 121 / 0 | |
| 50.10.0 | 121 / 0 | |
| 50.9.0 | 121 / 0 | |
| 50.8.0 | 121 / 0 | |
| 50.6.2 | 121 / 0 | |
| 50.6.1 | 121 / 0 | |
| 50.6.0 | 121 / 0 | |
| 50.5.0 | 121 / 0 | |
| 50.4.1 | 121 / 0 | |
| 50.2.0 | 121 / 0 | |
| 50.1.0 | 121 / 0 | |
| 50.0.0 | 121 / 0 | |
| 49.17.0 | 121 / 0 | |
| 49.16.0 | 121 / 0 | |
| 49.15.0 | 121 / 0 | |
| 49.11.0 | 121 / 0 |
v50.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v50.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v50.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v50.12.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.9.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.6.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.6.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v50.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v49.17.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v49.16.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v49.15.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v49.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.