@atlaskit/task-decision
Tasks and decisions react components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@atlaskit/tmp-editor-statsig | AI (phantom-deps): Same Atlassian org scope; phantom dep pattern is consistent with monorepo tooling/config usage. | ai | |
| phantom-deps | phantom-dep:@atlassian/react-compiler-gating | AI (phantom-deps): Same Atlassian org; declared for config/tooling purposes, not a runtime import — consistent with monorepo patterns. | ai | |
| phantom-deps | phantom-dep:@atlaskit/platform-feature-flags | AI (phantom-deps): Same-org Atlassian phantom dep; consistent with Atlassian monorepo patterns. No security risk. | ai | |
| provenance | no-provenance | AI (provenance): Established Atlassian package with 3200+ day history; lack of provenance attestation is not a meaningful risk signal here. | ai | |
| dependencies | unvetted-dep:@atlaskit/tmp-editor-statsig | AI (dependencies): First-party @atlaskit scoped dependency from the same Atlassian org. | ai | |
| dependencies | unvetted-dep:@atlaskit/util-service-support | AI (dependencies): First-party @atlaskit scoped dependency from the same Atlassian org. | ai | |
| dependencies | unvetted-dep:@atlaskit/platform-feature-flags | AI (dependencies): First-party @atlaskit scoped dependency from the same Atlassian org. | ai | |
| dependencies | unvetted-dep:@atlaskit/icon | AI (dependencies): First-party @atlaskit scoped dependency from the same Atlassian org; expected for this UI component package. | ai | |
| dependencies | unvetted-dep:@atlaskit/afm-i18n-platform-elements-task-decision | AI (dependencies): First-party @atlaskit scoped i18n dependency from the same Atlassian org. | ai | |
| phantom-deps | phantom-dep:@atlaskit/tokens | AI (phantom-deps): Same-org phantom dep in an Atlassian monorepo package; type-only or transitive usage is expected. | ai | |
| phantom-deps | phantom-dep:@atlaskit/afm-i18n-platform-elements-task-decision | AI (phantom-deps): Same-org phantom dep in an Atlassian monorepo package; indirect usage pattern is expected. | ai | |
| dependencies | unvetted-dep:@atlaskit/analytics-namespaced-context | AI (dependencies): First-party @atlaskit scoped dependency from the same Atlassian org. | ai | |
| dependencies | unvetted-dep:@compiled/react | AI (dependencies): Atlassian's own CSS-in-JS library; standard dependency across the @atlaskit ecosystem. | ai | |
| dependencies | unvetted-dep:@atlaskit/tokens | AI (dependencies): First-party @atlaskit scoped dependency from the same Atlassian org. | ai | |
| dependencies | unvetted-dep:@atlaskit/analytics-next | AI (dependencies): First-party @atlaskit scoped dependency from the same Atlassian org. | ai |
Versions (showing 51 of 108)
| Version | Deps | Published |
|---|---|---|
| 21.7.3 | 12 / 16 | |
| 21.7.2 | 12 / 16 | |
| 21.7.1 | 12 / 16 | |
| 21.7.0 | 12 / 16 | |
| 21.6.2 | 12 / 16 | |
| 21.6.1 | 12 / 16 | |
| 21.6.0 | 12 / 16 | |
| 21.5.0 | 12 / 16 | |
| 21.4.18 | 12 / 16 | |
| 21.4.17 | 12 / 16 | |
| 21.4.16 | 12 / 16 | |
| 21.4.15 | 12 / 16 | |
| 21.4.14 | 12 / 16 | |
| 21.4.13 | 12 / 16 | |
| 21.4.12 | 12 / 16 | |
| 21.4.11 | 12 / 16 | |
| 21.4.10 | 12 / 16 | |
| 21.4.9 | 12 / 16 | |
| 21.4.8 | 12 / 16 | |
| 21.4.7 | 12 / 16 | |
| 21.4.6 | 12 / 16 | |
| 21.4.5 | 12 / 16 | |
| 21.4.4 | 12 / 16 | |
| 21.4.3 | 12 / 16 | |
| 21.4.2 | 12 / 16 | |
| 21.4.1 | 12 / 16 | |
| 21.4.0 | 12 / 16 | |
| 21.3.0 | 12 / 16 | |
| 21.2.5 | 12 / 16 | |
| 21.2.4 | 12 / 16 | |
| 21.2.3 | 12 / 16 | |
| 21.2.2 | 12 / 16 | |
| 21.2.1 | 12 / 16 | |
| 21.2.0 | 11 / 17 | |
| 21.1.2 | 11 / 17 | |
| 21.1.1 | 11 / 17 | |
| 21.1.0 | 11 / 17 | |
| 21.0.2 | 11 / 17 | |
| 21.0.1 | 11 / 17 | |
| 21.0.0 | 11 / 17 | |
| 20.2.5 | 11 / 17 | |
| 20.2.4 | 11 / 17 | |
| 20.2.3 | 11 / 17 | |
| 20.2.2 | 11 / 17 | |
| 20.2.1 | 11 / 17 | |
| 20.2.0 | 11 / 17 | |
| 20.1.19 | 11 / 17 | |
| 20.1.18 | 11 / 17 | |
| 20.1.17 | 11 / 17 | |
| 20.1.16 | 11 / 17 | |
| 20.1.15 | 11 / 17 |
v21.7.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.7.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.6.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v21.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.