← Home

@carbon/ibm-products-web-components

Carbon for IBM Products Web Components

31
Versions
Apache-2.0
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

carbon-design-systemcarbon-botalisonjosephleechasejeffreychewsstrubbergtay1orjones

Keywords

carboncarbon design systemcarbon communitycarbon for ibm productscarbon for ibm products web componentsweb components

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:es-custom/components/about-modal/_story-assets/ansible-logo.svg.js AI (source-diff): Encoded SVG data URI in story asset, not obfuscated code. ai
source-diff obfuscated-file:es/components/about-modal/_story-assets/ansible-logo.svg.js AI (source-diff): Encoded SVG data URI in story asset, not obfuscated code. ai
publish-pattern new-deps-added AI (publish-pattern): Known IBM/Figma/Lit ecosystem packages, not suspicious. ai
source-diff obfuscated-file:es-custom/components/page-header/_story-assets/2x1.jpg.js AI (source-diff): Base64 image data, not obfuscated code. ai
source-diff obfuscated-file:es/components/page-header/_story-assets/2x1.jpg.js AI (source-diff): Base64 image data, not obfuscated code. ai
source-diff obfuscated-file:es-custom/components/page-header/_story-assets/3x2.jpg.js AI (source-diff): Base64 image data, not obfuscated code. ai
source-diff obfuscated-file:es/components/page-header/_story-assets/3x2.jpg.js AI (source-diff): Base64 image data, not obfuscated code. ai
source-diff obfuscated-file:es-custom/components/side-panel/side-panel.scss.js AI (source-diff): Minified CSS string, build output. ai
source-diff obfuscated-file:es-custom/components/full-page-error/full-page-error.scss.js AI (source-diff): Minified CSS string, build output. ai
source-diff obfuscated-file:es/components/full-page-error/assets/error403SVG.js AI (source-diff): SVG icon asset, not obfuscated code. ai
source-diff obfuscated-file:es-custom/components/user-avatar/user-avatar.scss.js AI (source-diff): Minified CSS string, build output. ai
source-diff obfuscated-file:es-custom/components/tearsheet/tearsheet.scss.js AI (source-diff): Minified CSS string, build output. ai
source-diff obfuscated-file:es-custom/components/full-page-error/assets/error403SVG.js AI (source-diff): SVG icon asset, not obfuscated code. ai
source-diff obfuscated-file:es/components/user-avatar/user-avatar.scss.js AI (source-diff): Minified CSS string, build output. ai
source-diff obfuscated-file:es/components/full-page-error/full-page-error.scss.js AI (source-diff): Minified CSS string, build output. ai
semgrep semgrep:dynamic-require AI (semgrep): Webpack loader require(this.resourcePath) is standard bundler-loader pattern, not arbitrary code load. ai
source-diff obfuscated-file:es/components/about-modal/about-modal.scss.js AI (source-diff): Minified compiled CSS, same pattern across component styles. ai
source-diff source-size-tripled AI (source-diff): Growth from added component style bundles, not injected payload. ai
source-diff large-new-source-files AI (source-diff): New compiled scss.js files per component, expected for this design-system package. ai
source-diff obfuscated-file:es-custom/components/about-modal/about-modal.scss.js AI (source-diff): Minified compiled CSS in a lit css`` template, not obfuscated code. ai
source-diff obfuscated-file:es/components/add-select/add-select.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template) — standard build artifact for this Carbon web components package. ai
source-diff obfuscated-file:es-custom/components/add-select/add-select-body.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template) — standard build artifact for this Carbon web components package. ai
source-diff obfuscated-file:es/components/add-select/add-select-body.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template) — standard build artifact for this Carbon web components package. ai
source-diff obfuscated-file:es-custom/components/add-select/add-select-content.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template) — standard build artifact for this Carbon web components package. ai
source-diff obfuscated-file:es/components/add-select/add-select-content.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template) — standard build artifact for this Carbon web components package. ai
source-diff obfuscated-file:es-custom/components/add-select/add-select-row.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template) — standard build artifact for this Carbon web components package. ai
source-diff obfuscated-file:es/components/add-select/add-select-row.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template) — standard build artifact for this Carbon web components package. ai
source-diff obfuscated-file:es-custom/components/add-select/add-select.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template) — standard build artifact for this Carbon web components package. ai
source-diff obfuscated-file:es-custom/components/edit-in-place/edit-in-place.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template) — standard build artifact for this Carbon web components package. ai
source-diff obfuscated-file:es/components/edit-in-place/edit-in-place.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template) — standard build artifact for this Carbon web components package. ai
source-diff obfuscated-file:es-custom/components/action-set/action-set.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template literal) — standard build output for this web component library. ai
provenance publisher-changed AI (provenance): Package uses GitHub Actions CI with SLSA provenance attestation; automated publisher is expected and documented in publishConfig. ai
source-diff obfuscated-file:es/components/coachmark/coachmark-beacon/coachmark-beacon.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template literal) — standard build output for this web component library. ai
source-diff obfuscated-file:es-custom/components/coachmark/coachmark-beacon/coachmark-beacon.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template literal) — standard build output for this web component library. ai
source-diff obfuscated-file:es/components/checklist/checklist.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template literal) — standard build output for this web component library. ai
source-diff obfuscated-file:es-custom/components/checklist/checklist.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template literal) — standard build output for this web component library. ai
source-diff obfuscated-file:es/components/big-number/big-number.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template literal) — standard build output for this web component library. ai
source-diff obfuscated-file:es-custom/components/big-number/big-number.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template literal) — standard build output for this web component library. ai
source-diff obfuscated-file:es/components/big-number/big-number-skeleton.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template literal) — standard build output for this web component library. ai
source-diff obfuscated-file:es-custom/components/big-number/big-number-skeleton.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template literal) — standard build output for this web component library. ai
source-diff obfuscated-file:es/components/action-set/action-set.scss.js AI (source-diff): Minified CSS-in-JS (Lit css template literal) — standard build output for this web component library. ai
phantom-deps phantom-dep:@ibm/telemetry-js AI (phantom-deps): Used via CLI (ibmtelemetry) in postinstall script and config files, not direct import; stable false positive. ai
phantom-deps phantom-dep:@carbon/ibm-products-styles AI (phantom-deps): Same-org style package; consumed as CSS/SCSS, not JS import — stable false positive for this package. ai
phantom-deps phantom-dep:@carbon/styles AI (phantom-deps): Same-org peer/style dependency; not directly imported but used transitively — stable false positive for Carbon packages. ai
install-scripts install-script:postinstall AI (install-scripts): IBM telemetry postinstall is standard for Carbon packages; matches declared @ibm/telemetry-js dep and telemetry.yml config. ai

Versions (showing 31 of 31)

Version Deps Published
0.42.0 11 / 39
0.41.0 11 / 38
0.40.0 10 / 38
0.39.0 10 / 38
0.38.0 10 / 38
0.37.0 10 / 38
0.36.0 10 / 38
0.33.0 10 / 45
0.31.0 9 / 43
0.29.0 9 / 42
0.20.1 6 / 38
0.20.0 6 / 38
0.19.0 6 / 44
0.18.0 5 / 44
0.17.0 5 / 44
0.16.0 5 / 44
0.15.0 5 / 44
0.14.0 5 / 44
0.13.0 4 / 43
0.12.0 4 / 42
0.11.0 4 / 42
0.10.0 4 / 40
0.9.0 4 / 40
0.8.0 4 / 40
0.6.1 4 / 37
0.6.0 4 / 37
0.5.0 4 / 37
0.4.0 4 / 37
0.3.0 4 / 36
0.2.0 4 / 36
0.1.0 4 / 36

v0.33.0

8 findings
HIGH New obfuscated file: es-custom/components/page-header/_story-assets/2x1.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/page-header/_story-assets/2x1.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/page-header/_story-assets/3x2.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/page-header/_story-assets/3x2.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/about-modal/_story-assets/ansible-logo.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/about-modal/_story-assets/ansible-logo.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carbon-bot → GitHub Actions (on 2026-02-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carbon-bot) on 2026-02-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.31.0

8 findings
HIGH New obfuscated file: es-custom/components/page-header/_story-assets/2x1.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/page-header/_story-assets/2x1.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/page-header/_story-assets/3x2.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/page-header/_story-assets/3x2.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/about-modal/_story-assets/ansible-logo.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/about-modal/_story-assets/ansible-logo.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carbon-bot → GitHub Actions (on 2026-01-21, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carbon-bot) on 2026-01-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.29.0

5 findings
HIGH New obfuscated file: es-custom/components/page-header/_story-assets/2x1.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/page-header/_story-assets/2x1.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/page-header/_story-assets/3x2.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/page-header/_story-assets/3x2.jpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.0

11 findings
HIGH New obfuscated file: es-custom/components/about-modal/about-modal.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/about-modal/about-modal.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/full-page-error/assets/error403SVG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/full-page-error/assets/error403SVG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/full-page-error/full-page-error.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/full-page-error/full-page-error.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/side-panel/side-panel.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/tearsheet/tearsheet.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/user-avatar/user-avatar.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/user-avatar/user-avatar.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.0

7 findings
HIGH New obfuscated file: es-custom/components/about-modal/about-modal.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/about-modal/about-modal.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/side-panel/side-panel.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/tearsheet/tearsheet.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/user-avatar/user-avatar.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/user-avatar/user-avatar.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.0

7 findings
HIGH New obfuscated file: es-custom/components/about-modal/about-modal.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/about-modal/about-modal.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/side-panel/side-panel.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/tearsheet/tearsheet.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es-custom/components/user-avatar/user-avatar.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/user-avatar/user-avatar.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.0

2 findings
HIGH New obfuscated file: es/components/user-avatar/user-avatar.scss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v0.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.