@atlaskit/smart-card
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@atlassian/react-compiler-gating | AI (phantom-deps): Same-org Atlassian scoped build/compiler utility; declared but not directly imported is expected for config-level deps. | ai | |
| phantom-deps | phantom-dep:@atlaskit/motion | AI (phantom-deps): Same @atlaskit org scope; phantom-dep pattern is consistent with this package's peer/optional dependency structure. | ai | |
| dependencies | unvetted-dep:@atlaskit/icon-priority | AI (dependencies): Internal @atlaskit org dependency published by the same Atlassian team; not a third-party risk. Stable pattern for this monorepo package. | ai | |
| dependencies | unvetted-dep:@atlaskit/legacy-custom-icons | AI (dependencies): Internal @atlaskit org dependency published by the same Atlassian team; not a third-party risk. Stable pattern for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@atlaskit/icon-lab | AI (phantom-deps): Same-org @atlaskit scope phantom dep; typical of large Atlassian monorepo packages where deps are declared for tooling but not directly imported. | ai | |
| phantom-deps | phantom-dep:@atlaskit/icon-priority | AI (phantom-deps): Same-org @atlaskit scope phantom dep; typical of large Atlassian monorepo packages where deps are declared for tooling but not directly imported. | ai | |
| phantom-deps | phantom-dep:@atlaskit/link-test-helpers | AI (phantom-deps): Same-org @atlaskit/* monorepo peer/dev deps declared but not directly imported in every file — expected pattern for Atlaskit packages. | ai | |
| phantom-deps | phantom-dep:facepaint | AI (phantom-deps): Referenced in config files only (e.g. emotion/styled config), not directly imported — common pattern in Atlaskit design system packages. | ai | |
| phantom-deps | phantom-dep:@atlaskit/afm-i18n-platform-linking-platform-smart-card | AI (phantom-deps): Same-org @atlaskit/* monorepo peer/dev deps declared but not directly imported in every file — expected pattern for Atlaskit packages. | ai | |
| source-diff | obfuscated-file:dist/cjs/view/HoverCard/components/views/unauthorised/graphics.js | AI (source-diff): Long lines are SVG path coordinate data in @compiled/babel-plugin generated output — not obfuscation. Stable false positive for this Atlaskit package's build pipeline. | ai | |
| source-diff | obfuscated-file:dist/es2019/view/HoverCard/components/views/unauthorised/graphics.js | AI (source-diff): Long lines are SVG path coordinate data in @compiled/babel-plugin generated output — not obfuscation. Stable false positive for this Atlaskit package's build pipeline. | ai | |
| source-diff | obfuscated-file:dist/esm/view/HoverCard/components/views/unauthorised/graphics.js | AI (source-diff): Long lines are SVG path coordinate data in @compiled/babel-plugin generated output — not obfuscation. Stable false positive for this Atlaskit package's build pipeline. | ai | |
| phantom-deps | phantom-dep:@atlaskit/avatar | AI (phantom-deps): Same-org @atlaskit/* monorepo peer/dev deps declared but not directly imported in every file — expected pattern for Atlaskit packages. | ai | |
| phantom-deps | phantom-dep:@atlaskit/icon-file-type | AI (phantom-deps): Same-org @atlaskit/* monorepo peer/dev deps declared but not directly imported in every file — expected pattern for Atlaskit packages. | ai | |
| provenance | no-provenance | AI (provenance): Atlassian publishes all @atlaskit/* packages without Sigstore provenance; this is a stable pattern for this publisher and not a security concern. | ai |
Versions (showing 100 of 318)
| Version | Deps | Published |
|---|---|---|
| 43.26.11 | 64 / 36 | |
| 43.26.10 | 64 / 36 | |
| 43.26.9 | 64 / 36 | |
| 43.26.8 | 64 / 36 | |
| 43.26.7 | 64 / 36 | |
| 43.26.6 | 64 / 36 | |
| 43.26.5 | 64 / 36 | |
| 43.26.4 | 64 / 36 | |
| 43.26.3 | 63 / 36 | |
| 43.26.2 | 63 / 36 | |
| 43.26.1 | 63 / 36 | |
| 43.26.0 | 63 / 36 | |
| 43.25.16 | 63 / 36 | |
| 43.25.15 | 63 / 36 | |
| 43.25.14 | 62 / 36 | |
| 43.25.13 | 62 / 36 | |
| 43.25.12 | 62 / 36 | |
| 43.25.11 | 62 / 36 | |
| 43.25.10 | 62 / 36 | |
| 43.25.9 | 63 / 36 | |
| 43.25.8 | 63 / 36 | |
| 43.25.7 | 63 / 36 | |
| 43.25.6 | 63 / 36 | |
| 43.25.5 | 63 / 36 | |
| 43.25.4 | 63 / 36 | |
| 43.25.3 | 63 / 36 | |
| 43.25.2 | 63 / 36 | |
| 43.25.1 | 63 / 36 | |
| 43.25.0 | 63 / 36 | |
| 43.24.10 | 63 / 36 | |
| 43.24.9 | 63 / 36 | |
| 43.24.8 | 63 / 36 | |
| 43.24.7 | 63 / 36 | |
| 43.24.6 | 63 / 36 | |
| 43.24.5 | 63 / 36 | |
| 43.24.4 | 63 / 36 | |
| 43.24.3 | 63 / 36 | |
| 43.24.2 | 62 / 36 | |
| 43.24.1 | 62 / 36 | |
| 43.24.0 | 62 / 36 | |
| 43.23.7 | 62 / 36 | |
| 43.23.6 | 62 / 36 | |
| 43.23.5 | 62 / 36 | |
| 43.23.4 | 62 / 36 | |
| 43.23.3 | 62 / 36 | |
| 43.23.2 | 62 / 36 | |
| 43.23.1 | 62 / 36 | |
| 43.23.0 | 62 / 36 | |
| 43.22.5 | 62 / 36 | |
| 43.22.4 | 62 / 36 | |
| 43.22.3 | 62 / 36 | |
| 43.22.2 | 62 / 36 | |
| 43.22.1 | 62 / 36 | |
| 43.22.0 | 62 / 36 | |
| 43.21.0 | 62 / 36 | |
| 43.20.8 | 62 / 36 | |
| 43.20.7 | 62 / 36 | |
| 43.20.6 | 62 / 36 | |
| 43.20.5 | 62 / 36 | |
| 43.20.4 | 62 / 36 | |
| 43.20.3 | 61 / 37 | |
| 43.20.2 | 61 / 37 | |
| 43.20.1 | 61 / 37 | |
| 43.20.0 | 61 / 36 | |
| 43.19.0 | 61 / 36 | |
| 43.18.1 | 61 / 36 | |
| 43.18.0 | 61 / 37 | |
| 43.17.7 | 61 / 37 | |
| 43.17.6 | 61 / 37 | |
| 43.17.5 | 61 / 37 | |
| 43.17.4 | 61 / 37 | |
| 43.17.3 | 61 / 37 | |
| 43.17.2 | 61 / 37 | |
| 43.17.1 | 61 / 37 | |
| 43.17.0 | 61 / 37 | |
| 43.16.0 | 62 / 37 | |
| 43.15.1 | 62 / 37 | |
| 43.15.0 | 62 / 37 | |
| 43.14.5 | 62 / 37 | |
| 43.14.4 | 62 / 37 | |
| 43.14.3 | 62 / 37 | |
| 43.14.2 | 62 / 37 | |
| 43.14.1 | 62 / 37 | |
| 43.14.0 | 62 / 37 | |
| 43.13.0 | 62 / 37 | |
| 43.12.3 | 61 / 37 | |
| 43.12.2 | 62 / 37 | |
| 43.12.1 | 62 / 36 | |
| 43.12.0 | 62 / 36 | |
| 43.11.3 | 61 / 36 | |
| 43.11.2 | 61 / 36 | |
| 43.11.1 | 61 / 36 | |
| 43.11.0 | 61 / 36 | |
| 43.10.2 | 61 / 36 | |
| 43.10.1 | 61 / 36 | |
| 43.10.0 | 61 / 36 | |
| 43.9.1 | 61 / 36 | |
| 43.9.0 | 61 / 36 | |
| 43.8.1 | 61 / 36 | |
| 43.8.0 | 61 / 36 |
v43.25.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.25.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.25.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.25.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.25.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.25.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.25.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.25.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.24.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.24.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.24.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.24.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.24.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.24.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.24.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.24.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.24.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.24.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.24.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.23.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.23.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.23.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.23.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.23.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.23.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.23.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.22.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.22.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.22.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.22.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.20.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.20.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.20.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.20.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.20.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.20.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.20.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.20.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.19.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.18.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.17.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.17.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.17.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.17.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.17.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.17.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.17.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.14.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.14.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.14.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.14.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.13.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.12.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.12.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.12.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.11.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.11.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.11.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.10.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.10.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v43.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.