@digital-realty/ix-widget
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:markdown-it | AI (dependencies): markdown-it is a well-known, widely-used library; stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established org package with 271 versions; no provenance is consistent across all releases. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Peer/re-export dep in a Lit+React wrapper library; config-only reference is expected. | ai | |
| phantom-deps | phantom-dep:@lit/react | AI (phantom-deps): Used in React wrapper export; config-only reference is expected for this library. | ai | |
| phantom-deps | phantom-dep:@material/web | AI (phantom-deps): UI component dep; config-only reference consistent with web component library pattern. | ai | |
| phantom-deps | phantom-dep:@digital-realty/ix-dialog | AI (phantom-deps): Same-org component dep; indirect usage via composition is expected. | ai | |
| phantom-deps | phantom-dep:mobx-persist-store | AI (phantom-deps): State persistence dep; config-only reference expected in this library. | ai | |
| phantom-deps | phantom-dep:@digital-realty/ix-list | AI (phantom-deps): Same-org component dep; indirect usage via composition is expected. | ai | |
| phantom-deps | phantom-dep:@adobe/lit-mobx | AI (phantom-deps): State management dep; config-only reference expected in this library. | ai | |
| phantom-deps | phantom-dep:@digital-realty/ix-accordion | AI (phantom-deps): Same-org component dep; indirect usage via composition is expected. | ai |
Versions (showing 80 of 80)
| Version | Deps | Published |
|---|---|---|
| 2.3.7 | 14 / 22 | |
| 2.3.6 | 14 / 22 | |
| 2.3.4 | 14 / 22 | |
| 2.3.3 | 14 / 23 | |
| 2.3.2 | 14 / 23 | |
| 2.3.1 | 14 / 23 | |
| 2.2.31 | 14 / 24 | |
| 2.2.15 | 14 / 23 | |
| 2.2.12 | 14 / 23 | |
| 2.2.5 | 14 / 23 | |
| 2.1.59 | 14 / 23 | |
| 2.1.56 | 14 / 23 | |
| 2.1.55 | 14 / 23 | |
| 2.1.54 | 14 / 23 | |
| 2.1.53 | 14 / 23 | |
| 2.1.52 | 14 / 23 | |
| 2.1.51 | 14 / 23 | |
| 2.1.46 | 15 / 23 | |
| 2.1.45 | 15 / 23 | |
| 2.1.44 | 14 / 23 | |
| 2.1.43 | 14 / 23 | |
| 2.1.42 | 14 / 23 | |
| 2.1.41 | 13 / 23 | |
| 2.1.40 | 13 / 23 | |
| 2.1.39 | 13 / 23 | |
| 2.1.38 | 13 / 23 | |
| 2.1.37 | 13 / 23 | |
| 2.1.36 | 13 / 23 | |
| 2.1.35 | 13 / 23 | |
| 2.1.34 | 13 / 23 | |
| 2.1.33 | 13 / 23 | |
| 2.1.32 | 12 / 23 | |
| 2.1.31 | 12 / 23 | |
| 2.1.30 | 12 / 23 | |
| 2.1.29 | 12 / 23 | |
| 2.1.28 | 12 / 23 | |
| 2.1.27 | 12 / 23 | |
| 2.1.26 | 12 / 23 | |
| 2.1.25 | 12 / 23 | |
| 2.1.24 | 12 / 24 | |
| 2.1.23 | 12 / 24 | |
| 2.1.22 | 12 / 24 | |
| 2.1.21 | 13 / 20 | |
| 2.1.20 | 13 / 20 | |
| 2.1.19 | 13 / 20 | |
| 2.1.18 | 13 / 20 | |
| 2.1.17 | 13 / 20 | |
| 2.1.16 | 13 / 20 | |
| 2.1.15 | 13 / 20 | |
| 2.1.14 | 13 / 20 | |
| 2.1.13 | 13 / 20 | |
| 2.1.12 | 13 / 20 | |
| 2.1.11 | 13 / 20 | |
| 2.1.10 | 13 / 20 | |
| 2.1.9 | 13 / 20 | |
| 2.1.8 | 13 / 20 | |
| 2.1.7 | 13 / 20 | |
| 2.1.6 | 13 / 20 | |
| 2.1.5 | 13 / 20 | |
| 2.1.4 | 13 / 20 | |
| 2.0.20 | 13 / 20 | |
| 2.0.19 | 13 / 20 | |
| 2.0.18 | 13 / 20 | |
| 2.0.17 | 13 / 20 | |
| 2.0.16 | 13 / 20 | |
| 2.0.15 | 13 / 20 | |
| 2.0.14 | 13 / 20 | |
| 2.0.13 | 13 / 20 | |
| 2.0.12 | 13 / 20 | |
| 2.0.11 | 13 / 20 | |
| 2.0.10 | 13 / 20 | |
| 2.0.9 | 13 / 20 | |
| 2.0.8 | 13 / 20 | |
| 2.0.7 | 13 / 20 | |
| 2.0.6 | 13 / 20 | |
| 2.0.5 | 13 / 20 | |
| 2.0.4 | 13 / 20 | |
| 2.0.3 | 13 / 20 | |
| 2.0.2 | 13 / 20 | |
| 2.0.1 | 13 / 20 |
v2.3.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.56
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.55
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.54
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.53
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.52
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.4
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nicholasnewlands) than the most recent previously approved version (dlr-pi-devops) on 2024-10-08, but nicholasnewlands is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.0.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.