← Home

@atlaskit/atlassian-context

20
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

atlassianartifactteam

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-takeover AI (maintainer-change): Legitimate transition from atlaskit to atlassianartifactteam — both are Atlassian org accounts. ai
maintainer-change maintainer-added AI (maintainer-change): atlassianartifactteam is Atlassian's bulk-publish account with 8600+ approved packages. ai
maintainer-change maintainer-removed AI (maintainer-change): Old atlaskit account replaced by atlassianartifactteam; internal org migration. ai
provenance publisher-changed AI (provenance): Publisher change reflects Atlassian's internal migration to atlassianartifactteam. ai
provenance missing-githead AI (provenance): Publish environment change consistent with org-wide migration to new publish account. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Atlaskit monorepo uses 0.0.0 as a convention for initial package versions; not a malware signal for this publisher. ai

Versions (showing 20 of 20)

Version Deps Published
1.1.1 1 / 1
1.1.0 1 / 1
1.0.0 1 / 1
0.11.0 1 / 1
0.10.0 1 / 1
0.9.0 1 / 0
0.8.0 1 / 0
0.7.0 1 / 0
0.6.1 1 / 0
0.6.0 1 / 6
0.5.0 1 / 7
0.4.0 1 / 8
0.3.2 1 / 8
0.3.1 1 / 8
0.3.0 1 / 8
0.2.0 1 / 8
0.1.0 1 / 8
0.0.2 1 / 8
0.0.1 1 / 8
0.0.0 1 / 8

v1.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.