@carbon/icon-helpers
Helpers used alongside icons for digital and software products using the Carbon Design System
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): @ibm/telemetry-js is IBM's official telemetry lib, added consistently across Carbon packages. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): CI/CD provenance-backed publish; monorepo maintainer churn, not compromise. | ai | |
| provenance | no-provenance | AI (provenance): Legacy Carbon release; provenance absence is common and benign. | ai | |
| email-domain | unclaimed-email:loveme.computer | AI (email-domain): Stale maintainer email on an established IBM package; no behavioral risk. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Carbon Design System monorepo package; publishing cadence varies per sub-package. SLSA provenance attestation confirms official CI/CD pipeline, ruling out account takeover. | ai | |
| phantom-deps | phantom-dep:@ibm/telemetry-js | AI (phantom-deps): Telemetry is invoked via CLI in postinstall script with a config file, not imported directly in source — this is the expected usage pattern. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): IBM telemetry postinstall is a documented, consistent pattern across all Carbon Design System packages. Not malicious — runs ibmtelemetry with a bundled config file. | ai | |
| dependencies | unvetted-dep:@ibm/telemetry-js | AI (dependencies): @ibm/telemetry-js is IBM's first-party telemetry package used across the entire Carbon ecosystem; stable dependency for this package. | ai |
Versions (showing 51 of 79)
| Version | Deps | Published |
|---|---|---|
| 10.76.0 | 1 / 3 | |
| 10.75.0 | 1 / 3 | |
| 10.74.0 | 1 / 3 | |
| 10.73.0 | 1 / 3 | |
| 10.72.0 | 1 / 3 | |
| 10.71.0 | 1 / 3 | |
| 10.70.0 | 1 / 3 | |
| 10.69.0 | 1 / 3 | |
| 10.68.0 | 1 / 3 | |
| 10.67.0 | 1 / 3 | |
| 10.66.0 | 1 / 3 | |
| 10.65.0 | 1 / 3 | |
| 10.63.0 | 1 / 3 | |
| 10.62.0 | 1 / 3 | |
| 10.61.0 | 1 / 3 | |
| 10.60.0 | 1 / 3 | |
| 10.59.0 | 1 / 3 | |
| 10.57.0 | 1 / 3 | |
| 10.56.0 | 1 / 3 | |
| 10.53.1 | 1 / 3 | |
| 10.52.0 | 1 / 3 | |
| 10.50.0 | 1 / 3 | |
| 10.47.0 | 1 / 3 | |
| 10.46.0 | 0 / 3 | |
| 10.45.1 | 0 / 3 | |
| 10.45.0 | 0 / 3 | |
| 10.44.0 | 0 / 2 | |
| 10.43.1 | 0 / 2 | |
| 10.43.0 | 0 / 2 | |
| 10.42.1 | 0 / 2 | |
| 10.42.0 | 0 / 2 | |
| 10.41.0 | 0 / 2 | |
| 10.40.0 | 0 / 2 | |
| 10.39.0 | 0 / 2 | |
| 10.38.0 | 0 / 2 | |
| 10.37.0 | 0 / 2 | |
| 10.36.0 | 0 / 2 | |
| 10.35.0 | 0 / 2 | |
| 10.34.0 | 0 / 2 | |
| 10.33.0 | 0 / 2 | |
| 10.32.0 | 0 / 2 | |
| 10.31.0 | 0 / 2 | |
| 10.30.0 | 0 / 2 | |
| 10.29.0 | 0 / 2 | |
| 10.28.3 | 1 / 2 | |
| 10.28.2 | 0 / 2 | |
| 10.28.1 | 0 / 2 | |
| 10.28.0 | 0 / 2 | |
| 10.27.0 | 0 / 2 | |
| 10.26.0 | 0 / 2 | |
| 10.25.0 | 0 / 2 |
v10.73.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v10.69.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carbon-bot) on 2025-12-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v10.61.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.57.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.56.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.53.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.52.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.50.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.46.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.45.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.45.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.44.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.43.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.43.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.42.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.42.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.41.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.35.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.34.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.33.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.30.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.29.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.28.3
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v10.28.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.28.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.