← Home

@carbon/icon-helpers

Helpers used alongside icons for digital and software products using the Carbon Design System

51
Versions
Apache-2.0
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

carbon-design-systemcarbon-botalisonjosephleechasejeffreychewsstrubbergtay1orjones

Keywords

ibmelementscarboncarbon-elementscarbon-design-systemcomponentsreact

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): @ibm/telemetry-js is IBM's official telemetry lib, added consistently across Carbon packages. ai
maintainer-change maintainer-added AI (maintainer-change): CI/CD provenance-backed publish; monorepo maintainer churn, not compromise. ai
provenance no-provenance AI (provenance): Legacy Carbon release; provenance absence is common and benign. ai
email-domain unclaimed-email:loveme.computer AI (email-domain): Stale maintainer email on an established IBM package; no behavioral risk. ai
publish-pattern dormant-publish AI (publish-pattern): Carbon Design System monorepo package; publishing cadence varies per sub-package. SLSA provenance attestation confirms official CI/CD pipeline, ruling out account takeover. ai
phantom-deps phantom-dep:@ibm/telemetry-js AI (phantom-deps): Telemetry is invoked via CLI in postinstall script with a config file, not imported directly in source — this is the expected usage pattern. ai
install-scripts install-script:postinstall AI (install-scripts): IBM telemetry postinstall is a documented, consistent pattern across all Carbon Design System packages. Not malicious — runs ibmtelemetry with a bundled config file. ai
dependencies unvetted-dep:@ibm/telemetry-js AI (dependencies): @ibm/telemetry-js is IBM's first-party telemetry package used across the entire Carbon ecosystem; stable dependency for this package. ai

Versions (showing 51 of 79)

View all versions
Version Deps Published
10.76.0 1 / 3
10.75.0 1 / 3
10.74.0 1 / 3
10.73.0 1 / 3
10.72.0 1 / 3
10.71.0 1 / 3
10.70.0 1 / 3
10.69.0 1 / 3
10.68.0 1 / 3
10.67.0 1 / 3
10.66.0 1 / 3
10.65.0 1 / 3
10.63.0 1 / 3
10.62.0 1 / 3
10.61.0 1 / 3
10.60.0 1 / 3
10.59.0 1 / 3
10.57.0 1 / 3
10.56.0 1 / 3
10.53.1 1 / 3
10.52.0 1 / 3
10.50.0 1 / 3
10.47.0 1 / 3
10.46.0 0 / 3
10.45.1 0 / 3
10.45.0 0 / 3
10.44.0 0 / 2
10.43.1 0 / 2
10.43.0 0 / 2
10.42.1 0 / 2
10.42.0 0 / 2
10.41.0 0 / 2
10.40.0 0 / 2
10.39.0 0 / 2
10.38.0 0 / 2
10.37.0 0 / 2
10.36.0 0 / 2
10.35.0 0 / 2
10.34.0 0 / 2
10.33.0 0 / 2
10.32.0 0 / 2
10.31.0 0 / 2
10.30.0 0 / 2
10.29.0 0 / 2
10.28.3 1 / 2
10.28.2 0 / 2
10.28.1 0 / 2
10.28.0 0 / 2
10.27.0 0 / 2
10.26.0 0 / 2
10.25.0 0 / 2

v10.73.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v10.69.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carbon-bot → GitHub Actions (on 2025-12-03, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carbon-bot) on 2025-12-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v10.61.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v10.57.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v10.56.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v10.53.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v10.52.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v10.50.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v10.47.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v10.46.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v10.45.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v10.45.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v10.44.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v10.43.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.43.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.42.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.42.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.41.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.40.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.39.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.38.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.37.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.36.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.35.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.34.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.33.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.32.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.31.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.30.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.29.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.28.3

1 finding
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.

v10.28.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.28.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.28.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.