@atlaskit/profilecard
A React component to display a card with user information.
3
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
atlassianartifactteam
Keywords
uiprofilecard
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@atlaskit/react-compiler-gating | AI (phantom-deps): Declared in atlassian.react-compiler.gating config; indirect import pattern is stable for this package. | ai | |
| dependencies | unvetted-dep:@atlassian/react-compiler-gating | AI (dependencies): First-party Atlassian scoped package used for React compiler feature gating; consistent with Atlassian's internal tooling patterns. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is @atlaskit/feature-gate-js-client, same Atlassian org scope; not a suspicious third-party addition. | ai | |
| dependencies | unvetted-dep:@atlassian/studio-entry-link | AI (dependencies): Same Atlassian org scope; consistent with this package's established dependency pattern. | ai | |
| phantom-deps | phantom-dep:@atlaskit/feature-gate-js-client | AI (phantom-deps): Monorepo package; phantom deps in same org scope are typical of hoisted workspace dependencies. | ai | |
| phantom-deps | phantom-dep:@emotion/react | AI (phantom-deps): Monorepo package; phantom deps referenced in config files are typical of hoisted workspace dependencies. | ai | |
| phantom-deps | phantom-dep:@atlaskit/link | AI (phantom-deps): Monorepo package; phantom deps in same org scope are typical of hoisted workspace dependencies. | ai | |
| phantom-deps | phantom-dep:@atlaskit/logo | AI (phantom-deps): Monorepo package; phantom deps in same org scope are typical of hoisted workspace dependencies. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Monorepo package; phantom deps referenced in config files are typical of hoisted workspace dependencies. | ai | |
| dependencies | unvetted-dep:react-intl-next | AI (dependencies): react-intl-next is a version alias for the well-known react-intl library; its use in Atlassian UI components is expected and benign. | ai | |
| provenance | no-provenance | AI (provenance): Atlassian publishes the entire @atlaskit/* ecosystem without Sigstore provenance; this is consistent across all their packages and not a security concern. | ai | |
| phantom-deps | phantom-dep:@atlaskit/tokens | AI (phantom-deps): Same-org phantom dep flag for @atlaskit/tokens; consistent with Atlaskit monorepo build patterns, not a security concern. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Lodash phantom dep is a common false positive in monorepo/build-tool setups; no security concern for this established Atlaskit package. | ai |