@atlaskit/rovo-agent-components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/esm/ui/agent-avatar/generated-avatars/assets/intercom-agent.js | AI (source-diff): Same SVG path data pattern in ESM build output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/es2019/ui/agent-avatar/generated-avatars/assets/intercom-agent.js | AI (source-diff): Same SVG path data pattern in ES2019 build output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/ui/agent-avatar/generated-avatars/assets/intercom-agent.js | AI (source-diff): Long lines are SVG path data in compiled React component output, not obfuscation. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@atlassian/react-compiler-gating | AI (phantom-deps): Same-org Atlassian package used as config/gating infrastructure; not directly imported, no malicious behavior. | ai | |
| dependencies | unvetted-dep:react-intl-next | AI (dependencies): react-intl-next is an Atlassian-maintained alias for react-intl used consistently across the Atlaskit ecosystem; not a security risk for this package. | ai | |
| phantom-deps | phantom-dep:@atlaskit/browser-apis | AI (phantom-deps): Same-org Atlaskit dependency declared for transitive use in monorepo context. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-magnetic-di | AI (phantom-deps): Atlaskit monorepo package; react-magnetic-di is used in config/test files rather than direct imports. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a standard peer dependency for React component libraries; declared in config files but not directly imported is a normal pattern. | ai | |
| phantom-deps | phantom-dep:@atlaskit/tokens | AI (phantom-deps): Same-org Atlaskit package; phantom dep pattern is expected for Atlassian component libraries using design tokens via config rather than direct imports. | ai | |
| provenance | no-provenance | AI (provenance): Atlassian's atlassianartifactteam publisher has 242 approved packages; lack of Sigstore provenance is consistent across their catalog and not a meaningful risk signal for this org. | ai |
Versions (showing 51 of 66)
| Version | Deps | Published |
|---|---|---|
| 8.2.0 | 26 / 13 | |
| 8.1.7 | 26 / 13 | |
| 8.1.6 | 26 / 13 | |
| 8.1.5 | 26 / 13 | |
| 8.1.4 | 26 / 13 | |
| 8.1.3 | 26 / 13 | |
| 8.1.2 | 26 / 13 | |
| 8.1.1 | 26 / 13 | |
| 8.1.0 | 26 / 13 | |
| 8.0.4 | 26 / 13 | |
| 8.0.3 | 26 / 13 | |
| 8.0.2 | 26 / 13 | |
| 8.0.1 | 26 / 13 | |
| 8.0.0 | 26 / 13 | |
| 7.5.3 | 25 / 13 | |
| 7.5.2 | 25 / 13 | |
| 7.5.1 | 25 / 13 | |
| 7.5.0 | 25 / 13 | |
| 7.4.4 | 25 / 13 | |
| 7.4.3 | 25 / 13 | |
| 7.4.2 | 25 / 13 | |
| 7.4.1 | 25 / 13 | |
| 7.4.0 | 25 / 13 | |
| 7.3.1 | 25 / 13 | |
| 7.3.0 | 25 / 13 | |
| 7.2.0 | 25 / 13 | |
| 7.1.0 | 25 / 13 | |
| 7.0.1 | 25 / 13 | |
| 7.0.0 | 24 / 14 | |
| 6.0.2 | 23 / 14 | |
| 6.0.1 | 23 / 14 | |
| 6.0.0 | 23 / 14 | |
| 5.3.0 | 23 / 14 | |
| 5.2.3 | 23 / 14 | |
| 5.2.2 | 23 / 14 | |
| 5.2.1 | 23 / 14 | |
| 5.2.0 | 23 / 14 | |
| 5.1.0 | 23 / 14 | |
| 5.0.0 | 23 / 14 | |
| 4.7.0 | 23 / 14 | |
| 4.6.0 | 23 / 13 | |
| 4.5.1 | 23 / 13 | |
| 4.5.0 | 23 / 13 | |
| 4.4.2 | 23 / 13 | |
| 4.4.1 | 23 / 13 | |
| 4.4.0 | 23 / 13 | |
| 4.3.2 | 23 / 13 | |
| 4.3.1 | 23 / 13 | |
| 4.3.0 | 23 / 13 | |
| 4.2.0 | 23 / 13 | |
| 4.1.0 | 22 / 13 |
v8.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.5.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.5.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.4.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.