@almadar/patterns
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Package is a legitimate UI pattern registry with no install scripts or runtime deps; provenance gap reflects a CI workflow change, not a security threat. | ai |
Versions (showing 51 of 167)
| Version | Deps | Published |
|---|---|---|
| 2.101.0 | 1 / 9 | |
| 2.100.0 | 1 / 9 | |
| 2.99.0 | 1 / 9 | |
| 2.98.0 | 1 / 9 | |
| 2.97.0 | 1 / 9 | |
| 2.96.0 | 1 / 9 | |
| 2.95.0 | 1 / 9 | |
| 2.94.0 | 1 / 9 | |
| 2.93.0 | 1 / 8 | |
| 2.92.0 | 1 / 8 | |
| 2.91.0 | 1 / 8 | |
| 2.90.0 | 1 / 8 | |
| 2.89.0 | 1 / 8 | |
| 2.88.1 | 1 / 8 | |
| 2.88.0 | 1 / 8 | |
| 2.87.0 | 1 / 8 | |
| 2.85.0 | 1 / 8 | |
| 2.83.0 | 1 / 8 | |
| 2.82.0 | 1 / 8 | |
| 2.81.0 | 1 / 8 | |
| 2.80.0 | 1 / 8 | |
| 2.79.0 | 1 / 8 | |
| 2.78.0 | 1 / 8 | |
| 2.77.0 | 1 / 8 | |
| 2.76.0 | 1 / 8 | |
| 2.75.0 | 1 / 8 | |
| 2.74.0 | 1 / 8 | |
| 2.73.0 | 1 / 8 | |
| 2.72.0 | 1 / 8 | |
| 2.71.0 | 1 / 8 | |
| 2.70.0 | 1 / 8 | |
| 2.69.0 | 1 / 8 | |
| 2.68.0 | 1 / 8 | |
| 2.67.0 | 1 / 8 | |
| 2.66.0 | 1 / 8 | |
| 2.65.0 | 1 / 8 | |
| 2.64.0 | 1 / 8 | |
| 2.63.0 | 1 / 8 | |
| 2.62.0 | 1 / 8 | |
| 2.61.0 | 1 / 8 | |
| 2.60.0 | 1 / 8 | |
| 2.59.0 | 1 / 8 | |
| 2.58.0 | 1 / 8 | |
| 2.57.0 | 1 / 8 | |
| 2.56.0 | 1 / 8 | |
| 2.55.0 | 1 / 8 | |
| 2.54.0 | 1 / 8 | |
| 2.53.0 | 1 / 8 | |
| 2.52.0 | 1 / 8 | |
| 2.51.0 | 1 / 8 | |
| 2.50.0 | 1 / 8 |
v2.101.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.100.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.99.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.98.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.97.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.96.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.95.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.94.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.93.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.92.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.91.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.90.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.89.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.88.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.88.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.87.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.85.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.83.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.82.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.81.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.80.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.79.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.78.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.77.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.76.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.75.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.74.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.73.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.72.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.71.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.