← Home

@carbon/ibm-products

Carbon for IBM Products

5
Versions
Apache-2.0
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

leechasecarbon-botelycheeatay1orjones

Keywords

carboncarbon design systemcarbon communitycarbon for cloud & cognitivecarbon for ibm products

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern dormant-publish AI (publish-pattern): Established IBM/Carbon org package with SLSA provenance; CI/CD publisher via GitHub Actions is consistent with org release cadence. ai
dependencies unvetted-dep:@carbon/utilities-react AI (dependencies): Same Carbon/IBM org scope; consistent with this package's dependency pattern. ai
dependencies unvetted-dep:@carbon-labs/react-resizer AI (dependencies): Carbon Labs org; expected dependency for IBM Products component library. ai
phantom-deps phantom-dep:@carbon/ibm-products-styles AI (phantom-deps): Companion styles package loaded by consumers via CSS/SCSS, not direct JS import; stable false positive. ai
install-scripts install-script:postinstall AI (install-scripts): IBM telemetry collection via ibmtelemetry CLI; documented pattern for all @carbon packages, stable across versions. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped Babel runtime; loaded by convention in transpiled output, not direct import. ai
phantom-deps phantom-dep:@carbon/telemetry AI (phantom-deps): Used via telemetry.yml config and postinstall CLI, not direct import; stable false positive for this package. ai
phantom-deps phantom-dep:@ibm/telemetry-js AI (phantom-deps): Referenced in config files as documented; not a direct import by design. ai

Versions (showing 5 of 5)

Version Deps Published
2.90.0 15 / 44
2.89.0 15 / 44
2.88.0 15 / 44
2.87.1 15 / 44
2.87.0 15 / 44

v2.90.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.88.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.87.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.87.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.