← Home

@carbon/charts-angular

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

carbon-bot

Keywords

chartsgraphsradargaugedonutpiesparklinetreetreemapheatmapwordcloudhistogramalluvialgeobarbulletscattermeterlineangularcomponentcarbonibmsvgdatatypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-takeover AI (maintainer-change): New maintainer matches longtime IBM contributor listed in package.json, not a hijack. ai
source-diff obfuscated-file:esm2022/lib/diagrams/nodes/cards/card-node.component.mjs AI (source-diff): Same Angular AOT build pattern, clean readable source. ai
source-diff obfuscated-file:esm2022/lib/charts/charts.module.mjs AI (source-diff): Same Angular AOT build pattern, clean readable source. ai
source-diff obfuscated-file:esm2022/lib/diagrams/edges/edge.component.mjs AI (source-diff): Same Angular AOT build pattern, clean readable source. ai
source-diff obfuscated-file:esm2022/index.mjs AI (source-diff): Index re-export file with base64 sourcemap tail, not obfuscated. ai
source-diff obfuscated-file:esm2022/lib/charts/index.mjs AI (source-diff): Index re-export file with base64 sourcemap tail, not obfuscated. ai
source-diff obfuscated-file:esm2022/lib/diagrams/nodes/shape/shape-node.component.mjs AI (source-diff): Same Angular AOT build pattern, clean readable source. ai
source-diff obfuscated-file:esm2022/lib/diagrams/edges/marker/marker.component.mjs AI (source-diff): Same Angular AOT build pattern, clean readable source. ai
source-diff obfuscated-file:esm2022/lib/charts/base-chart.component.mjs AI (source-diff): Angular AOT-compiled output with long metadata lines, not real obfuscation. ai
source-diff large-new-source-files AI (source-diff): Expected growth from Angular esm2022 build artifacts, not injected code. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): Known implicit Angular/TS runtime dep. ai
phantom-deps phantom-dep:@ibm/telemetry-js AI (phantom-deps): Official IBM telemetry lib referenced via config, standard for Carbon packages. ai
phantom-deps phantom-dep:@carbon/telemetry AI (phantom-deps): Same-org IBM telemetry dep; declared as runtime dependency, phantom-dep heuristic is a false positive here. ai

Versions (showing 51 of 79)

View all versions
Version Deps Published
1.27.17 3 / 0
1.27.16 3 / 0
1.27.14 3 / 0
1.27.13 3 / 0
1.27.12 3 / 0
1.27.11 3 / 0
1.27.10 3 / 0
1.27.8 3 / 0
1.27.3 3 / 0
1.27.2 3 / 0
1.27.0 3 / 0
1.26.1 3 / 0
1.26.0 3 / 0
1.25.1 3 / 0
1.25.0 3 / 0
1.24.0 3 / 0
1.23.17 3 / 0
1.23.16 3 / 0
1.23.15 3 / 0
1.23.14 3 / 0
1.23.13 3 / 0
1.23.12 3 / 0
1.23.11 3 / 0
1.23.10 3 / 0
1.23.9 3 / 0
1.23.8 3 / 0
1.23.7 3 / 0
1.23.6 3 / 0
1.23.5 3 / 0
1.23.4 3 / 0
1.23.3 3 / 0
1.23.2 3 / 0
1.23.1 3 / 0
1.23.0 3 / 0
1.22.21 3 / 0
1.22.20 3 / 0
1.22.19 3 / 0
1.22.18 3 / 0
1.22.17 3 / 0
1.22.16 3 / 0
1.22.15 3 / 0
1.22.14 3 / 0
1.22.13 3 / 0
1.22.12 3 / 0
1.22.11 3 / 0
1.22.10 3 / 0
1.22.9 3 / 0
1.22.8 3 / 0
1.22.7 3 / 0
1.22.6 3 / 0
1.22.5 3 / 0

v1.27.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.23.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.