@atlaskit/media-ui
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@atlassian/react-compiler-gating | AI (phantom-deps): Atlassian-scoped build/config dep, not directly imported at runtime; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@popperjs/core | AI (phantom-deps): Declared but not directly imported; stable false positive for this established Atlassian UI package. | ai | |
| dependencies | unvetted-dep:@atlaskit/legacy-custom-icons | AI (dependencies): Same Atlassian org scope (@atlaskit); this is a first-party dependency expected across all @atlaskit packages and poses no independent risk. | ai | |
| phantom-deps | phantom-dep:@atlaskit/dropdown-menu | AI (phantom-deps): Same-org Atlassian package declared but not directly imported; consistent with Atlaskit's monorepo structure and not a security concern. | ai | |
| provenance | no-provenance | AI (provenance): Atlassian's atlassianartifactteam publisher has 252 approved packages without provenance; this is a stable publishing pattern for this org, not a security concern. | ai | |
| phantom-deps | phantom-dep:@atlaskit/css | AI (phantom-deps): Same-org @atlaskit scoped package declared but not directly imported; minor packaging concern, not a security risk for this well-established Atlassian package. | ai |
Versions (showing 51 of 65)
| Version | Deps | Published |
|---|---|---|
| 30.10.0 | 37 / 19 | |
| 30.9.0 | 37 / 19 | |
| 30.8.0 | 37 / 19 | |
| 30.7.5 | 37 / 19 | |
| 30.7.4 | 37 / 19 | |
| 30.7.3 | 37 / 19 | |
| 30.7.2 | 37 / 19 | |
| 30.7.1 | 37 / 19 | |
| 30.7.0 | 37 / 19 | |
| 30.6.1 | 37 / 19 | |
| 30.6.0 | 37 / 19 | |
| 30.5.1 | 37 / 19 | |
| 30.5.0 | 37 / 19 | |
| 30.4.0 | 37 / 19 | |
| 30.3.1 | 37 / 19 | |
| 30.3.0 | 36 / 20 | |
| 30.2.0 | 36 / 20 | |
| 30.1.0 | 36 / 20 | |
| 30.0.1 | 36 / 20 | |
| 30.0.0 | 34 / 20 | |
| 29.3.1 | 34 / 21 | |
| 29.3.0 | 34 / 21 | |
| 29.2.5 | 34 / 21 | |
| 29.2.4 | 34 / 21 | |
| 29.2.3 | 34 / 21 | |
| 29.2.2 | 34 / 21 | |
| 29.2.1 | 34 / 20 | |
| 29.2.0 | 34 / 20 | |
| 29.1.1 | 34 / 20 | |
| 29.1.0 | 34 / 20 | |
| 29.0.0 | 34 / 20 | |
| 28.7.42 | 34 / 20 | |
| 28.7.41 | 34 / 20 | |
| 28.7.40 | 34 / 20 | |
| 28.7.39 | 34 / 20 | |
| 28.7.38 | 34 / 20 | |
| 28.7.37 | 34 / 20 | |
| 28.7.36 | 34 / 20 | |
| 28.7.35 | 34 / 20 | |
| 28.7.34 | 34 / 20 | |
| 28.7.33 | 34 / 20 | |
| 28.7.32 | 34 / 20 | |
| 28.7.31 | 34 / 20 | |
| 28.7.30 | 34 / 20 | |
| 28.7.29 | 34 / 20 | |
| 28.7.28 | 34 / 20 | |
| 28.7.27 | 35 / 20 | |
| 28.7.26 | 35 / 20 | |
| 28.7.25 | 35 / 20 | |
| 28.7.24 | 35 / 19 | |
| 28.7.23 | 35 / 19 |
v30.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.7.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.7.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.7.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.7.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v30.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.