@carbon/motion
Motion helpers for digital and software products using the Carbon Design System
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-removed | AI (maintainer-change): Carbon monorepo migrated to GitHub Actions CI publishing; human maintainer removal is expected and stable. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Apparent dormancy reflects CI publisher transition, not account takeover; SLSA provenance confirms legitimate CI origin. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): IBM telemetry postinstall is standard across Carbon Design System packages; not malicious. | ai | |
| phantom-deps | phantom-dep:@ibm/telemetry-js | AI (phantom-deps): @ibm/telemetry-js is a declared runtime dependency used via CLI in postinstall, not a direct import — stable false positive. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 11.46.0 | 1 / 4 | |
| 11.45.0 | 1 / 4 | |
| 11.44.0 | 1 / 4 | |
| 11.43.0 | 1 / 2 | |
| 11.41.0 | 1 / 2 | |
| 11.40.0 | 1 / 2 | |
| 11.38.0 | 1 / 2 | |
| 11.30.0 | 1 / 2 | |
| 11.29.0 | 1 / 2 |
v11.46.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.44.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.43.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.41.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.40.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.38.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.30.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.
v11.29.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.