@codecademy/gamut-kit
Styleguide & Component library for Codecademy
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): Org account rename from codecademy to codecademy-eng; confirmed same maintainer by email match across 122 approved packages. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): codecademy-eng is the renamed org account, not a new external party. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): codecademy account removal is the other side of the org rename; same entity. | ai | |
| provenance | no-provenance | AI (provenance): Large org monorepo with long publish history; absence of Sigstore attestation is not a risk signal here. | ai | |
| dependencies | unvetted-dep:component-test-setup | AI (dependencies): component-test-setup is a test utility, also flagged as phantom (not directly imported); stable low-risk pattern for this package. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): High-frequency monorepo CI publishing pattern; 8939 versions published over 5+ years is consistent with automated pipelines. | ai | |
| phantom-deps | phantom-dep:@codecademy/gamut-patterns | AI (phantom-deps): Same-org aggregator pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@codecademy/gamut | AI (phantom-deps): Kit package re-exports org deps; not directly imported by design. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal design system kit; sparse README and no keywords are expected for internal tooling packages. | ai | |
| phantom-deps | phantom-dep:@codecademy/gamut-illustrations | AI (phantom-deps): Same-org aggregator pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@codecademy/variance | AI (phantom-deps): Same-org aggregator pattern; phantom-dep is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:component-test-setup | AI (phantom-deps): Referenced in config files per finding; not a real phantom dep. | ai | |
| phantom-deps | phantom-dep:@codecademy/gamut-icons | AI (phantom-deps): Same-org aggregator pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@codecademy/gamut-tests | AI (phantom-deps): Same-org aggregator pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@codecademy/gamut-styles | AI (phantom-deps): Same-org aggregator pattern; stable false positive. | ai |
Versions (showing 100 of 213)
| Version | Deps | Published |
|---|---|---|
| 0.6.516 | 8 / 0 | |
| 0.6.515 | 8 / 0 | |
| 0.6.514 | 8 / 0 | |
| 0.6.513 | 8 / 0 | |
| 0.6.512 | 8 / 0 | |
| 0.6.511 | 8 / 0 | |
| 0.6.510 | 8 / 0 | |
| 0.6.509 | 8 / 0 | |
| 0.6.508 | 8 / 0 | |
| 0.6.507 | 8 / 0 | |
| 0.6.506 | 8 / 0 | |
| 0.6.505 | 8 / 0 | |
| 0.6.504 | 8 / 0 | |
| 0.6.503 | 8 / 0 | |
| 0.6.502 | 8 / 0 | |
| 0.6.501 | 8 / 0 | |
| 0.6.500 | 8 / 0 | |
| 0.6.499 | 8 / 0 | |
| 0.6.498 | 8 / 0 | |
| 0.6.497 | 8 / 0 | |
| 0.6.496 | 8 / 0 | |
| 0.6.495 | 8 / 0 | |
| 0.6.494 | 8 / 0 | |
| 0.6.493 | 8 / 0 | |
| 0.6.492 | 8 / 0 | |
| 0.6.491 | 8 / 0 | |
| 0.6.490 | 8 / 0 | |
| 0.6.489 | 8 / 0 | |
| 0.6.488 | 8 / 0 | |
| 0.6.487 | 8 / 0 | |
| 0.6.486 | 8 / 0 | |
| 0.6.485 | 8 / 0 | |
| 0.6.484 | 8 / 0 | |
| 0.6.483 | 8 / 0 | |
| 0.6.482 | 8 / 0 | |
| 0.6.481 | 8 / 0 | |
| 0.6.480 | 8 / 0 | |
| 0.6.479 | 8 / 0 | |
| 0.6.478 | 8 / 0 | |
| 0.6.477 | 8 / 0 | |
| 0.6.476 | 8 / 0 | |
| 0.6.475 | 8 / 0 | |
| 0.6.474 | 8 / 0 | |
| 0.6.473 | 8 / 0 | |
| 0.6.472 | 8 / 0 | |
| 0.6.471 | 8 / 0 | |
| 0.6.470 | 8 / 0 | |
| 0.6.469 | 8 / 0 | |
| 0.6.468 | 8 / 0 | |
| 0.6.467 | 8 / 0 | |
| 0.6.466 | 8 / 0 | |
| 0.6.465 | 8 / 0 | |
| 0.6.464 | 8 / 0 | |
| 0.6.463 | 8 / 0 | |
| 0.6.462 | 8 / 0 | |
| 0.6.461 | 8 / 0 | |
| 0.6.460 | 8 / 0 | |
| 0.6.459 | 8 / 0 | |
| 0.6.458 | 8 / 0 | |
| 0.6.457 | 8 / 0 | |
| 0.6.456 | 8 / 0 | |
| 0.6.455 | 8 / 0 | |
| 0.6.454 | 8 / 0 | |
| 0.6.453 | 8 / 0 | |
| 0.6.452 | 8 / 0 | |
| 0.6.451 | 8 / 0 | |
| 0.6.450 | 8 / 0 | |
| 0.6.449 | 8 / 0 | |
| 0.6.448 | 8 / 0 | |
| 0.6.447 | 8 / 0 | |
| 0.6.446 | 8 / 0 | |
| 0.6.445 | 8 / 0 | |
| 0.6.444 | 8 / 0 | |
| 0.6.443 | 8 / 0 | |
| 0.6.442 | 8 / 0 | |
| 0.6.441 | 8 / 0 | |
| 0.6.440 | 8 / 0 | |
| 0.6.439 | 8 / 0 | |
| 0.6.438 | 8 / 0 | |
| 0.6.437 | 8 / 0 | |
| 0.6.436 | 8 / 0 | |
| 0.6.435 | 8 / 0 | |
| 0.6.434 | 8 / 0 | |
| 0.6.433 | 8 / 0 | |
| 0.6.432 | 8 / 0 | |
| 0.6.431 | 8 / 0 | |
| 0.6.430 | 8 / 0 | |
| 0.6.429 | 8 / 0 | |
| 0.6.428 | 8 / 0 | |
| 0.6.427 | 8 / 0 | |
| 0.6.426 | 8 / 0 | |
| 0.6.425 | 8 / 0 | |
| 0.6.424 | 8 / 0 | |
| 0.6.423 | 8 / 0 | |
| 0.6.422 | 8 / 0 | |
| 0.6.421 | 8 / 0 | |
| 0.6.420 | 8 / 0 | |
| 0.6.419 | 8 / 0 | |
| 0.6.418 | 8 / 0 | |
| 0.6.417 | 8 / 0 |
v0.6.501
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.500
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.499
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.498
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.497
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.496
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.495
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.494
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.493
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.492
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.491
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.490
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.489
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.488
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.487
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.486
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.485
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.484
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.483
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.482
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.481
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.480
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.479
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.478
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.477
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.476
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.475
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.474
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.473
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.472
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.471
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.470
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.469
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.468
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.467
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.466
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.465
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.464
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.463
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.462
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.461
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.460
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.459
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.458
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.457
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.456
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.455
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.454
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.453
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.452
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.451
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.450
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.449
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.448
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.447
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.446
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.445
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.444
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.443
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.442
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.441
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.440
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.439
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.438
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.437
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.436
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.435
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.434
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.433
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.432
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.431
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.430
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.429
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.428
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.427
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.426
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.425
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.424
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.423
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.422
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.421
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.420
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.419
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.418
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.417
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.