← Home

@clef-sh/design

Internal Clef design tokens (Tailwind v4 @theme + TS mirror). Implementation detail of the @clef-sh/* workspaces — not a public API.

7
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

spandrelsys

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@fontsource/instrument-serif AI (phantom-deps): Font package referenced in CSS config files, not JS imports; expected pattern for a design-token package. ai
phantom-deps phantom-dep:@fontsource-variable/jetbrains-mono AI (phantom-deps): Font package referenced in CSS config files, not JS imports; expected pattern for a design-token package. ai
phantom-deps phantom-dep:@fontsource-variable/instrument-sans AI (phantom-deps): Font package referenced in CSS config files, not JS imports; expected pattern for a design-token package. ai

Versions (showing 7 of 7)

Version Deps Published
0.1.8 3 / 1
0.1.7 3 / 1
0.1.6 3 / 1
0.1.5 3 / 1
0.1.4 3 / 1
0.1.3 0 / 0
0.1.2 0 / 0

v0.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.