@cloudscape-design/components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): AWS CI publisher releases frequently in short intervals; consistent history of approved versions. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Rapidly versioned large component library; new source files reflect new components, not injected code. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Active package with 1296 versions; dormant-publish is a false positive for this high-frequency publisher. | ai | |
| dependencies | unvetted-dep:@cloudscape-design/theming-runtime | AI (dependencies): First-party AWS Cloudscape package; stable dependency. | ai | |
| dependencies | unvetted-dep:@cloudscape-design/collection-hooks | AI (dependencies): First-party AWS Cloudscape package; stable dependency. | ai | |
| dependencies | unvetted-dep:mnth | AI (dependencies): Legitimate calendar utility; stable dependency of this package across versions. | ai | |
| provenance | no-provenance | AI (provenance): Established AWS CI publisher; lack of Sigstore provenance is common and not a risk signal here. | ai | |
| dependencies | unvetted-dep:@cloudscape-design/component-toolkit | AI (dependencies): First-party AWS Cloudscape package; stable dependency. | ai | |
| dependencies | unvetted-dep:weekstart | AI (dependencies): Legitimate week-start locale utility; stable dependency of this package. | ai | |
| dependencies | unvetted-dep:@cloudscape-design/test-utils-core | AI (dependencies): First-party AWS Cloudscape package; stable dependency. | ai |
Versions (showing 100 of 211)
| Version | Deps | Published |
|---|---|---|
| 3.0.1334 | 17 / 0 | |
| 3.0.1333 | 17 / 0 | |
| 3.0.1332 | 17 / 0 | |
| 3.0.1331 | 17 / 0 | |
| 3.0.1330 | 17 / 0 | |
| 3.0.1329 | 17 / 0 | |
| 3.0.1328 | 17 / 0 | |
| 3.0.1327 | 17 / 0 | |
| 3.0.1326 | 17 / 0 | |
| 3.0.1325 | 17 / 0 | |
| 3.0.1324 | 17 / 0 | |
| 3.0.1323 | 17 / 0 | |
| 3.0.1322 | 17 / 0 | |
| 3.0.1321 | 17 / 0 | |
| 3.0.1320 | 17 / 0 | |
| 3.0.1319 | 17 / 0 | |
| 3.0.1318 | 17 / 0 | |
| 3.0.1317 | 17 / 0 | |
| 3.0.1316 | 17 / 0 | |
| 3.0.1315 | 17 / 0 | |
| 3.0.1314 | 17 / 0 | |
| 3.0.1313 | 17 / 0 | |
| 3.0.1312 | 17 / 0 | |
| 3.0.1311 | 17 / 0 | |
| 3.0.1310 | 17 / 0 | |
| 3.0.1309 | 17 / 0 | |
| 3.0.1308 | 17 / 0 | |
| 3.0.1307 | 17 / 0 | |
| 3.0.1306 | 17 / 0 | |
| 3.0.1305 | 17 / 0 | |
| 3.0.1304 | 17 / 0 | |
| 3.0.1303 | 17 / 0 | |
| 3.0.1302 | 17 / 0 | |
| 3.0.1301 | 17 / 0 | |
| 3.0.1300 | 17 / 0 | |
| 3.0.1299 | 17 / 0 | |
| 3.0.1298 | 17 / 0 | |
| 3.0.1297 | 17 / 0 | |
| 3.0.1296 | 17 / 0 | |
| 3.0.1295 | 17 / 0 | |
| 3.0.1294 | 17 / 0 | |
| 3.0.1293 | 17 / 0 | |
| 3.0.1292 | 17 / 0 | |
| 3.0.1291 | 17 / 0 | |
| 3.0.1290 | 17 / 0 | |
| 3.0.1289 | 17 / 0 | |
| 3.0.1288 | 17 / 0 | |
| 3.0.1287 | 17 / 0 | |
| 3.0.1286 | 17 / 0 | |
| 3.0.1285 | 17 / 0 | |
| 3.0.1284 | 17 / 0 | |
| 3.0.1283 | 17 / 0 | |
| 3.0.1282 | 17 / 0 | |
| 3.0.1281 | 17 / 0 | |
| 3.0.1280 | 17 / 0 | |
| 3.0.1279 | 17 / 0 | |
| 3.0.1278 | 17 / 0 | |
| 3.0.1277 | 17 / 0 | |
| 3.0.1276 | 17 / 0 | |
| 3.0.1275 | 17 / 0 | |
| 3.0.1274 | 17 / 0 | |
| 3.0.1273 | 17 / 0 | |
| 3.0.1272 | 17 / 0 | |
| 3.0.1271 | 17 / 0 | |
| 3.0.1270 | 17 / 0 | |
| 3.0.1269 | 17 / 0 | |
| 3.0.1268 | 17 / 0 | |
| 3.0.1267 | 17 / 0 | |
| 3.0.1266 | 17 / 0 | |
| 3.0.1265 | 17 / 0 | |
| 3.0.1264 | 17 / 0 | |
| 3.0.1263 | 17 / 0 | |
| 3.0.1262 | 17 / 0 | |
| 3.0.1261 | 17 / 0 | |
| 3.0.1260 | 17 / 0 | |
| 3.0.1259 | 17 / 0 | |
| 3.0.1258 | 17 / 0 | |
| 3.0.1257 | 17 / 0 | |
| 3.0.1256 | 17 / 0 | |
| 3.0.1255 | 17 / 0 | |
| 3.0.1254 | 17 / 0 | |
| 3.0.1253 | 17 / 0 | |
| 3.0.1252 | 17 / 0 | |
| 3.0.1251 | 17 / 0 | |
| 3.0.1250 | 17 / 0 | |
| 3.0.1249 | 17 / 0 | |
| 3.0.1248 | 17 / 0 | |
| 3.0.1247 | 17 / 0 | |
| 3.0.1246 | 17 / 0 | |
| 3.0.1245 | 17 / 0 | |
| 3.0.1244 | 17 / 0 | |
| 3.0.1243 | 17 / 0 | |
| 3.0.1242 | 17 / 0 | |
| 3.0.1241 | 17 / 0 | |
| 3.0.1240 | 17 / 0 | |
| 3.0.1239 | 17 / 0 | |
| 3.0.1238 | 17 / 0 | |
| 3.0.1237 | 17 / 0 | |
| 3.0.1236 | 17 / 0 | |
| 3.0.1235 | 17 / 0 |
v3.0.1334
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1333
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1332
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1331
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1330
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1329
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1328
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1327
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1326
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1325
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1324
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1323
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1322
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1321
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1320
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1319
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1318
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1317
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1316
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1315
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1314
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1313
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1312
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1311
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1310
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1309
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1308
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1307
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1306
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1305
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1304
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1303
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1301
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1300
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1299
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1298
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1297
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1296
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1294
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1293
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1292
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1291
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1290
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1289
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1288
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1285
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1284
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1283
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1282
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1281
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1280
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1279
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1278
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1277
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1276
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1275
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1274
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1273
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1272
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1270
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1269
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1268
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1267
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1266
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1265
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1264
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1263
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1262
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1261
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1260
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1259
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1258
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1257
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1255
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1254
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1253
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1252
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1251
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1250
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1249
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1248
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1247
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1246
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1245
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1244
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1243
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1242
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1241
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1240
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1239
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1238
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1237
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1236
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1235
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.