@atlaskit/rovo-agent-components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:react-intl-next | AI (dependencies): react-intl-next is an Atlassian-maintained alias for react-intl used consistently across the Atlaskit ecosystem; not a security risk for this package. | ai | |
| phantom-deps | phantom-dep:react-magnetic-di | AI (phantom-deps): Atlaskit monorepo package; react-magnetic-di is used in config/test files rather than direct imports. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@atlaskit/browser-apis | AI (phantom-deps): Same-org Atlaskit dependency declared for transitive use in monorepo context. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@atlaskit/tokens | AI (phantom-deps): Same-org Atlaskit package; phantom dep pattern is expected for Atlassian component libraries using design tokens via config rather than direct imports. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a standard peer dependency for React component libraries; declared in config files but not directly imported is a normal pattern. | ai | |
| provenance | no-provenance | AI (provenance): Atlassian's atlassianartifactteam publisher has 242 approved packages; lack of Sigstore provenance is consistent across their catalog and not a meaningful risk signal for this org. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 5.2.1 | 23 / 14 | |
| 5.2.0 | 23 / 14 | |
| 5.1.0 | 23 / 14 | |
| 5.0.0 | 23 / 14 | |
| 4.7.0 | 23 / 14 | |
| 4.6.0 | 23 / 13 | |
| 4.5.1 | 23 / 13 | |
| 4.5.0 | 23 / 13 | |
| 4.4.2 | 23 / 13 | |
| 4.4.1 | 23 / 13 | |
| 4.4.0 | 23 / 13 | |
| 4.3.2 | 23 / 13 | |
| 4.3.1 | 23 / 13 | |
| 4.3.0 | 23 / 13 | |
| 4.2.0 | 23 / 13 | |
| 4.1.0 | 22 / 13 | |
| 4.0.0 | 22 / 13 | |
| 3.49.2 | 23 / 12 | |
| 3.49.1 | 23 / 12 | |
| 3.48.2 | 23 / 11 | |
| 3.48.1 | 23 / 11 | |
| 3.48.0 | 23 / 11 | |
| 3.47.0 | 23 / 11 | |
| 3.46.3 | 23 / 11 | |
| 3.41.0 | 23 / 11 | |
| 3.38.1 | 23 / 11 | |
| 3.36.3 | 23 / 11 | |
| 3.16.1 | 20 / 9 | |
| 3.10.0 | 22 / 8 |
v5.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.49.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.49.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.48.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.48.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.48.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.47.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.46.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.38.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.36.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.