← Home

@ant-design/colors

Color palettes calculator of Ant Design

31
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

afc163zombiejchenshuai2144arvinxxmadcccranranup123

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Maintainer list cleanup during major version bump within the Ant Design org; publisher zombiej is a trusted long-term contributor. ai
provenance publisher-changed AI (provenance): Both afc163 and zombiej are long-standing Ant Design team members; intra-team publisher rotation is expected for this org-scoped package. ai
maintainer-change maintainer-added AI (maintainer-change): Maintainer expansion on an established Ant Design package; consistent with ecosystem growth and team collaboration. ai
phantom-deps phantom-dep:tslint AI (phantom-deps): tslint was accidentally placed in dependencies instead of devDependencies; it is not imported at runtime. Benign packaging mistake consistent across versions of this package. ai
dependencies unvetted-dep:tslint AI (dependencies): tslint is a dev linting tool mistakenly listed as a runtime dep; not actually used at runtime. No security risk for this package. ai
dependencies unvetted-dep:tinycolor2 AI (dependencies): tinycolor2 is a legitimate, widely-used color library; appropriate dependency for a color palette calculator. ai
typosquat typosquat.levenshtein:cors AI (typosquat): @ant-design/colors is a scoped package from the official Ant Design org, not a typosquat of cors. Levenshtein match is spurious. ai
provenance no-provenance AI (provenance): Established package with 4M weekly downloads and a trusted publisher; lack of Sigstore provenance is not a meaningful risk signal here. ai

Versions (showing 31 of 31)

Version Deps Published
8.0.1 1 / 14
8.0.0 1 / 14
7.2.1 1 / 13
7.2.0 1 / 13
7.1.0 1 / 12
7.0.2 1 / 9
7.0.1 1 / 9
7.0.0 1 / 10
6.0.0 1 / 13
5.1.1 1 / 13
5.1.0 1 / 14
5.0.1 1 / 13
5.0.0 1 / 14
4.0.5 1 / 14
4.0.4 1 / 14
4.0.3 1 / 14
4.0.2 1 / 14
4.0.1 1 / 14
4.0.0 1 / 14
3.2.2 1 / 14
3.2.1 1 / 14
3.2.0 1 / 14
3.1.0 1 / 14
3.0.1 1 / 12
3.0.0 1 / 12
2.1.0 1 / 13
2.0.4 1 / 8
2.0.3 2 / 8
2.0.2 2 / 8
2.0.1 2 / 8
2.0.0 1 / 9

v4.0.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.