@ant-design/colors
Color palettes calculator of Ant Design
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer list cleanup during major version bump within the Ant Design org; publisher zombiej is a trusted long-term contributor. | ai | |
| provenance | publisher-changed | AI (provenance): Both afc163 and zombiej are long-standing Ant Design team members; intra-team publisher rotation is expected for this org-scoped package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Maintainer expansion on an established Ant Design package; consistent with ecosystem growth and team collaboration. | ai | |
| phantom-deps | phantom-dep:tslint | AI (phantom-deps): tslint was accidentally placed in dependencies instead of devDependencies; it is not imported at runtime. Benign packaging mistake consistent across versions of this package. | ai | |
| dependencies | unvetted-dep:tslint | AI (dependencies): tslint is a dev linting tool mistakenly listed as a runtime dep; not actually used at runtime. No security risk for this package. | ai | |
| dependencies | unvetted-dep:tinycolor2 | AI (dependencies): tinycolor2 is a legitimate, widely-used color library; appropriate dependency for a color palette calculator. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @ant-design/colors is a scoped package from the official Ant Design org, not a typosquat of cors. Levenshtein match is spurious. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 4M weekly downloads and a trusted publisher; lack of Sigstore provenance is not a meaningful risk signal here. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 8.0.1 | 1 / 14 | |
| 8.0.0 | 1 / 14 | |
| 7.2.1 | 1 / 13 | |
| 7.2.0 | 1 / 13 | |
| 7.1.0 | 1 / 12 | |
| 7.0.2 | 1 / 9 | |
| 7.0.1 | 1 / 9 | |
| 7.0.0 | 1 / 10 | |
| 6.0.0 | 1 / 13 | |
| 5.1.1 | 1 / 13 | |
| 5.1.0 | 1 / 14 | |
| 5.0.1 | 1 / 13 | |
| 5.0.0 | 1 / 14 | |
| 4.0.5 | 1 / 14 | |
| 4.0.4 | 1 / 14 | |
| 4.0.3 | 1 / 14 | |
| 4.0.2 | 1 / 14 | |
| 4.0.1 | 1 / 14 | |
| 4.0.0 | 1 / 14 | |
| 3.2.2 | 1 / 14 | |
| 3.2.1 | 1 / 14 | |
| 3.2.0 | 1 / 14 | |
| 3.1.0 | 1 / 14 | |
| 3.0.1 | 1 / 12 | |
| 3.0.0 | 1 / 12 | |
| 2.1.0 | 1 / 13 | |
| 2.0.4 | 1 / 8 | |
| 2.0.3 | 2 / 8 | |
| 2.0.2 | 2 / 8 | |
| 2.0.1 | 2 / 8 | |
| 2.0.0 | 1 / 9 |
v4.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.