@atlaskit/media-card
Includes all media card related components, CardView, CardViewSmall, Card...
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@atlaskit/progress-bar | AI (phantom-deps): Same org scope (@atlaskit); phantom dep pattern is consistent with this monorepo package. | ai | |
| phantom-deps | phantom-dep:@atlassian/react-compiler-gating | AI (phantom-deps): Config-only reference within the same Atlassian org scope; not directly imported at runtime. | ai | |
| phantom-deps | phantom-dep:classnames | AI (phantom-deps): Phantom deps in monorepo packages are common; declared but unused deps don't affect runtime security. | ai | |
| phantom-deps | phantom-dep:eventemitter2 | AI (phantom-deps): Phantom deps in monorepo packages are common; declared but unused deps don't affect runtime security. | ai | |
| phantom-deps | phantom-dep:@atlaskit/theme | AI (phantom-deps): Same-org scoped phantom deps typical in Atlassian monorepo; no security impact. | ai | |
| phantom-deps | phantom-dep:@atlaskit/link | AI (phantom-deps): Same-org scoped phantom deps typical in Atlassian monorepo; no security impact. | ai | |
| phantom-deps | phantom-dep:lru_map | AI (phantom-deps): Phantom deps in monorepo packages are common; declared but unused deps don't affect runtime security. | ai | |
| provenance | no-provenance | AI (provenance): Atlassian publishes this package via their artifact pipeline without Sigstore provenance; this is consistent across all their releases and not a security concern for this trusted publisher. | ai |
Versions (showing 100 of 161)
| Version | Deps | Published |
|---|---|---|
| 81.4.16 | 33 / 28 | |
| 81.4.15 | 33 / 28 | |
| 81.4.14 | 33 / 28 | |
| 81.4.13 | 33 / 28 | |
| 81.4.12 | 33 / 28 | |
| 81.4.11 | 33 / 28 | |
| 81.4.10 | 33 / 28 | |
| 81.4.9 | 33 / 28 | |
| 81.4.8 | 33 / 28 | |
| 81.4.7 | 33 / 28 | |
| 81.4.6 | 33 / 28 | |
| 81.4.5 | 33 / 28 | |
| 81.4.4 | 33 / 28 | |
| 81.4.3 | 33 / 28 | |
| 81.4.2 | 33 / 28 | |
| 81.4.1 | 33 / 28 | |
| 81.4.0 | 33 / 28 | |
| 81.3.4 | 33 / 28 | |
| 81.3.3 | 33 / 28 | |
| 81.3.2 | 33 / 28 | |
| 81.3.1 | 33 / 28 | |
| 81.3.0 | 33 / 28 | |
| 81.2.6 | 33 / 28 | |
| 81.2.5 | 33 / 28 | |
| 81.2.4 | 33 / 28 | |
| 81.2.3 | 33 / 28 | |
| 81.2.2 | 33 / 28 | |
| 81.2.1 | 33 / 28 | |
| 81.2.0 | 33 / 28 | |
| 81.1.6 | 33 / 28 | |
| 81.1.5 | 33 / 28 | |
| 81.1.4 | 33 / 28 | |
| 81.1.3 | 33 / 28 | |
| 81.1.2 | 33 / 28 | |
| 81.1.1 | 32 / 29 | |
| 81.1.0 | 32 / 29 | |
| 81.0.4 | 32 / 29 | |
| 81.0.3 | 32 / 29 | |
| 81.0.2 | 32 / 29 | |
| 81.0.1 | 32 / 29 | |
| 81.0.0 | 32 / 29 | |
| 80.8.14 | 32 / 29 | |
| 80.8.13 | 32 / 29 | |
| 80.8.12 | 32 / 29 | |
| 80.8.11 | 32 / 29 | |
| 80.8.10 | 32 / 29 | |
| 80.8.9 | 32 / 29 | |
| 80.8.6 | 32 / 29 | |
| 80.8.5 | 32 / 29 | |
| 80.8.4 | 32 / 29 | |
| 80.8.3 | 32 / 29 | |
| 80.8.2 | 32 / 29 | |
| 80.8.1 | 32 / 29 | |
| 80.8.0 | 32 / 29 | |
| 80.7.5 | 31 / 29 | |
| 80.7.4 | 31 / 30 | |
| 80.7.3 | 31 / 30 | |
| 80.7.2 | 31 / 30 | |
| 80.7.1 | 31 / 30 | |
| 80.7.0 | 31 / 30 | |
| 80.6.1 | 31 / 30 | |
| 80.6.0 | 31 / 30 | |
| 80.5.9 | 31 / 30 | |
| 80.5.8 | 31 / 30 | |
| 80.5.7 | 31 / 30 | |
| 80.5.6 | 31 / 30 | |
| 80.5.5 | 31 / 30 | |
| 80.5.4 | 31 / 30 | |
| 80.5.3 | 31 / 30 | |
| 80.5.2 | 31 / 30 | |
| 80.5.1 | 31 / 30 | |
| 80.5.0 | 31 / 30 | |
| 80.4.11 | 31 / 30 | |
| 80.4.10 | 31 / 30 | |
| 80.4.9 | 31 / 30 | |
| 80.4.8 | 31 / 30 | |
| 80.4.7 | 31 / 30 | |
| 80.4.6 | 31 / 29 | |
| 80.4.5 | 31 / 29 | |
| 80.4.4 | 31 / 29 | |
| 80.4.3 | 31 / 29 | |
| 80.4.2 | 31 / 29 | |
| 80.4.1 | 31 / 29 | |
| 80.4.0 | 31 / 29 | |
| 80.3.4 | 32 / 29 | |
| 80.3.3 | 32 / 29 | |
| 80.3.2 | 32 / 29 | |
| 80.3.1 | 32 / 29 | |
| 80.3.0 | 32 / 29 | |
| 80.2.3 | 32 / 29 | |
| 80.2.2 | 32 / 29 | |
| 80.2.1 | 32 / 29 | |
| 80.2.0 | 32 / 29 | |
| 80.1.5 | 31 / 29 | |
| 80.1.4 | 31 / 29 | |
| 80.1.3 | 31 / 29 | |
| 80.1.2 | 31 / 29 | |
| 80.1.1 | 31 / 29 | |
| 80.1.0 | 31 / 29 | |
| 80.0.0 | 31 / 29 |
v81.4.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.3.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.3.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.3.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.2.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.2.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.2.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v81.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.