@carbon/icon-helpers
Helpers used alongside icons for digital and software products using the Carbon Design System
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): @ibm/telemetry-js is IBM's official telemetry lib, added consistently across Carbon packages. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): CI/CD provenance-backed publish; monorepo maintainer churn, not compromise. | ai | |
| provenance | no-provenance | AI (provenance): Legacy Carbon release; provenance absence is common and benign. | ai | |
| email-domain | unclaimed-email:loveme.computer | AI (email-domain): Stale maintainer email on an established IBM package; no behavioral risk. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Carbon Design System monorepo package; publishing cadence varies per sub-package. SLSA provenance attestation confirms official CI/CD pipeline, ruling out account takeover. | ai | |
| phantom-deps | phantom-dep:@ibm/telemetry-js | AI (phantom-deps): Telemetry is invoked via CLI in postinstall script with a config file, not imported directly in source — this is the expected usage pattern. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): IBM telemetry postinstall is a documented, consistent pattern across all Carbon Design System packages. Not malicious — runs ibmtelemetry with a bundled config file. | ai | |
| dependencies | unvetted-dep:@ibm/telemetry-js | AI (dependencies): @ibm/telemetry-js is IBM's first-party telemetry package used across the entire Carbon ecosystem; stable dependency for this package. | ai |
Versions (showing 79 of 79)
| Version | Deps | Published |
|---|---|---|
| 10.76.0 | 1 / 3 | |
| 10.75.0 | 1 / 3 | |
| 10.74.0 | 1 / 3 | |
| 10.73.0 | 1 / 3 | |
| 10.72.0 | 1 / 3 | |
| 10.71.0 | 1 / 3 | |
| 10.70.0 | 1 / 3 | |
| 10.69.0 | 1 / 3 | |
| 10.68.0 | 1 / 3 | |
| 10.67.0 | 1 / 3 | |
| 10.66.0 | 1 / 3 | |
| 10.65.0 | 1 / 3 | |
| 10.63.0 | 1 / 3 | |
| 10.62.0 | 1 / 3 | |
| 10.61.0 | 1 / 3 | |
| 10.60.0 | 1 / 3 | |
| 10.59.0 | 1 / 3 | |
| 10.57.0 | 1 / 3 | |
| 10.56.0 | 1 / 3 | |
| 10.53.1 | 1 / 3 | |
| 10.52.0 | 1 / 3 | |
| 10.50.0 | 1 / 3 | |
| 10.47.0 | 1 / 3 | |
| 10.46.0 | 0 / 3 | |
| 10.45.1 | 0 / 3 | |
| 10.45.0 | 0 / 3 | |
| 10.44.0 | 0 / 2 | |
| 10.43.1 | 0 / 2 | |
| 10.43.0 | 0 / 2 | |
| 10.42.1 | 0 / 2 | |
| 10.42.0 | 0 / 2 | |
| 10.41.0 | 0 / 2 | |
| 10.40.0 | 0 / 2 | |
| 10.39.0 | 0 / 2 | |
| 10.38.0 | 0 / 2 | |
| 10.37.0 | 0 / 2 | |
| 10.36.0 | 0 / 2 | |
| 10.35.0 | 0 / 2 | |
| 10.34.0 | 0 / 2 | |
| 10.33.0 | 0 / 2 | |
| 10.32.0 | 0 / 2 | |
| 10.31.0 | 0 / 2 | |
| 10.30.0 | 0 / 2 | |
| 10.29.0 | 0 / 2 | |
| 10.28.3 | 1 / 2 | |
| 10.28.2 | 0 / 2 | |
| 10.28.1 | 0 / 2 | |
| 10.28.0 | 0 / 2 | |
| 10.27.0 | 0 / 2 | |
| 10.26.0 | 0 / 2 | |
| 10.25.0 | 0 / 2 | |
| 10.24.0 | 0 / 2 | |
| 10.23.0 | 0 / 2 | |
| 10.22.0 | 0 / 2 | |
| 10.21.0 | 0 / 2 | |
| 10.20.0 | 0 / 2 | |
| 10.19.0 | 0 / 2 | |
| 10.18.0 | 0 / 2 | |
| 10.17.0 | 0 / 2 | |
| 10.16.0 | 0 / 2 | |
| 10.15.0 | 0 / 2 | |
| 10.14.0 | 0 / 2 | |
| 10.13.0 | 0 / 2 | |
| 10.12.0 | 0 / 2 | |
| 10.11.0 | 0 / 2 | |
| 10.10.0 | 0 / 2 | |
| 10.9.0 | 0 / 2 | |
| 10.8.0 | 0 / 2 | |
| 10.7.0 | 0 / 2 | |
| 10.6.0 | 0 / 2 | |
| 10.5.2 | 0 / 2 | |
| 10.5.1 | 0 / 2 | |
| 10.5.0 | 0 / 2 | |
| 10.4.0 | 0 / 2 | |
| 10.3.0 | 0 / 2 | |
| 10.2.0 | 0 / 2 | |
| 10.1.1 | 0 / 2 | |
| 10.1.0 | 0 / 2 | |
| 10.0.0 | 0 / 2 |
v10.73.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v10.69.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carbon-bot) on 2025-12-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v10.61.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.57.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.56.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.53.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.52.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.50.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.46.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.45.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.45.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.44.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v10.43.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.43.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.42.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.42.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.41.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.35.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.34.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.33.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.30.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.29.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.28.3
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v10.28.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.28.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.20.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.9.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (carbon-bot) than the most recent previously approved version (joshblack) on 2020-06-16, but carbon-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v10.8.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (carbon-bot) than the most recent previously approved version (joshblack) on 2020-06-05, but carbon-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v10.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.6.0
2 findingsMaintainer email '[email protected]' uses domain 'loveme.computer' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.5.2
2 findingsMaintainer email '[email protected]' uses domain 'loveme.computer' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.5.1
2 findingsMaintainer email '[email protected]' uses domain 'loveme.computer' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.5.0
2 findingsMaintainer email '[email protected]' uses domain 'loveme.computer' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.4.0
2 findingsMaintainer email '[email protected]' uses domain 'loveme.computer' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.3.0
2 findingsMaintainer email '[email protected]' uses domain 'loveme.computer' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.2.0
2 findingsMaintainer email '[email protected]' uses domain 'loveme.computer' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.1.1
2 findingsMaintainer email '[email protected]' uses domain 'loveme.computer' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.1.0
2 findingsMaintainer email '[email protected]' uses domain 'loveme.computer' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v10.0.0
2 findingsMaintainer email '[email protected]' uses domain 'loveme.computer' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.