@australiangreens/ag-internal-components
Library of components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Publish workflow changed to CI/CD-based; gitHead absence reflects tooling change, not tampering. | ai | |
| provenance | no-provenance | AI (provenance): Established org package; lack of Sigstore provenance is common and not a risk signal here. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Legitimate org package with 153 versions and public GitHub repo; dormancy likely reflects org release cadence, not takeover. | ai | |
| phantom-deps | phantom-dep:core-js-pure | AI (phantom-deps): Known implicit dependency; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-transition-group | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/react-transition-group | AI (phantom-deps): Framework-scoped type package loaded by convention; stable false positive. | ai |
Versions (showing 55 of 55)
| Version | Deps | Published |
|---|---|---|
| 0.5.0 | 10 / 42 | |
| 0.4.3 | 10 / 41 | |
| 0.4.2 | 10 / 41 | |
| 0.4.1 | 10 / 41 | |
| 0.4.0 | 10 / 40 | |
| 0.3.21 | 10 / 40 | |
| 0.3.19 | 10 / 40 | |
| 0.3.18 | 10 / 40 | |
| 0.3.17 | 10 / 40 | |
| 0.3.16 | 10 / 40 | |
| 0.3.14 | 10 / 40 | |
| 0.3.13 | 10 / 40 | |
| 0.3.12 | 9 / 40 | |
| 0.3.10 | 9 / 40 | |
| 0.3.9 | 9 / 40 | |
| 0.3.8 | 9 / 40 | |
| 0.3.7 | 9 / 40 | |
| 0.3.6 | 9 / 40 | |
| 0.3.5 | 9 / 40 | |
| 0.3.4 | 9 / 40 | |
| 0.3.3 | 9 / 40 | |
| 0.3.2 | 9 / 40 | |
| 0.3.1 | 9 / 40 | |
| 0.3.0 | 9 / 40 | |
| 0.2.3 | 9 / 53 | |
| 0.2.2 | 9 / 53 | |
| 0.2.1 | 9 / 54 | |
| 0.2.0 | 9 / 54 | |
| 0.1.26 | 9 / 54 | |
| 0.1.25 | 9 / 54 | |
| 0.1.24 | 9 / 54 | |
| 0.1.23 | 9 / 54 | |
| 0.1.22 | 9 / 54 | |
| 0.1.21 | 9 / 54 | |
| 0.1.20 | 8 / 54 | |
| 0.1.19 | 8 / 54 | |
| 0.1.18 | 11 / 54 | |
| 0.1.17 | 11 / 54 | |
| 0.1.16 | 10 / 55 | |
| 0.1.15 | 10 / 55 | |
| 0.1.14 | 10 / 55 | |
| 0.1.13 | 10 / 55 | |
| 0.1.12 | 10 / 55 | |
| 0.1.11 | 10 / 55 | |
| 0.1.10 | 10 / 55 | |
| 0.1.9 | 10 / 55 | |
| 0.1.8 | 10 / 55 | |
| 0.1.7 | 10 / 55 | |
| 0.1.6 | 10 / 55 | |
| 0.1.5 | 10 / 55 | |
| 0.1.4 | 10 / 55 | |
| 0.1.3 | 10 / 55 | |
| 0.1.2 | 10 / 55 | |
| 0.1.1 | 10 / 55 | |
| 0.1.0 | 10 / 55 |
v0.1.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.19
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lukek-ag) than the most recent previously approved version (peterkmurphy-ag) on 2024-09-10, but lukek-ag is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.16
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (peterkmurphy-ag) than the most recent previously approved version (lukek-ag) on 2024-08-29, but peterkmurphy-ag is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.15
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (peterkmurphy-ag) than the most recent previously approved version (lukek-ag) on 2024-08-28, but peterkmurphy-ag is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.14
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lukek-ag) than the most recent previously approved version (anthonyblond) on 2024-08-28, but lukek-ag is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.10
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anthonyblond) than the most recent previously approved version (lukek-ag) on 2024-08-05, but anthonyblond is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.9
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anthonyblond) than the most recent previously approved version (lukek-ag) on 2024-08-05, but anthonyblond is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.3
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lukek-ag) than the most recent previously approved version (anthonyblond) on 2024-07-03, but lukek-ag is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.