@carbon/grid
Grid for digital and software products using the Carbon Design System
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): Official IBM telemetry package, consistent across Carbon monorepo releases. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Carbon monorepo publishes in batches via CI; gaps between releases are normal for this package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Transition to GitHub Actions automated publishing explains maintainer removal; SLSA provenance confirms CI integrity. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): IBM telemetry postinstall is standard across all @carbon/* packages; not malicious. | ai | |
| phantom-deps | phantom-dep:@ibm/telemetry-js | AI (phantom-deps): Referenced in telemetry.yml config for postinstall; not a JS import but legitimately used. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped @carbon/grid package from IBM; Levenshtein match to uuid is a false positive. | ai | |
| phantom-deps | phantom-dep:@carbon/layout | AI (phantom-deps): Same-org SCSS dependency; not directly imported in JS but used as a SCSS dependency. | ai |
Versions (showing 42 of 42)
| Version | Deps | Published |
|---|---|---|
| 11.56.0 | 2 / 2 | |
| 11.55.0 | 2 / 2 | |
| 11.54.0 | 2 / 2 | |
| 11.53.0 | 2 / 2 | |
| 11.52.0 | 2 / 2 | |
| 11.48.0 | 2 / 2 | |
| 11.46.0 | 2 / 2 | |
| 11.45.0 | 2 / 2 | |
| 11.44.0 | 2 / 2 | |
| 11.43.0 | 2 / 2 | |
| 11.41.0 | 2 / 2 | |
| 11.40.0 | 2 / 2 | |
| 11.39.0 | 2 / 2 | |
| 11.38.0 | 2 / 2 | |
| 11.36.0 | 2 / 2 | |
| 11.23.0 | 2 / 2 | |
| 11.22.0 | 2 / 2 | |
| 11.21.1 | 1 / 2 | |
| 11.21.0 | 1 / 2 | |
| 11.20.0 | 1 / 2 | |
| 11.19.0 | 1 / 2 | |
| 11.18.0 | 1 / 2 | |
| 11.17.1 | 1 / 2 | |
| 11.17.0 | 1 / 2 | |
| 11.16.1 | 1 / 2 | |
| 11.16.0 | 1 / 2 | |
| 11.15.0 | 1 / 2 | |
| 11.14.0 | 1 / 2 | |
| 11.13.0 | 1 / 2 | |
| 11.12.0 | 1 / 2 | |
| 11.11.0 | 1 / 2 | |
| 11.10.0 | 1 / 2 | |
| 11.9.0 | 1 / 2 | |
| 11.8.0 | 1 / 2 | |
| 11.7.0 | 1 / 2 | |
| 11.6.0 | 1 / 2 | |
| 11.5.0 | 1 / 2 | |
| 11.4.0 | 1 / 2 | |
| 11.3.0 | 1 / 2 | |
| 11.2.0 | 1 / 2 | |
| 11.1.0 | 1 / 2 | |
| 11.0.0 | 1 / 2 |
v11.23.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v11.22.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v11.21.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v11.21.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v11.20.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v11.19.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v11.18.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v11.17.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.16.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.