<!DOCTYPE html>
<html>
<head>
  <meta charset="UTF-8">
  <meta name="viewport" content="width=device-width, initial-scale=1.0">
  <title>@downforce/std.css — Greenflagged</title>
  <link rel="icon" href="data:image/svg+xml,<svg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 100 100'><rect width='100' height='100' rx='20' fill='%23227a68'/><text x='50' y='72' font-size='60' font-weight='800' font-family='system-ui' text-anchor='middle' fill='white'>G</text></svg>">
  <link rel="preconnect" href="https://fonts.googleapis.com">
  <link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
  <link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=JetBrains+Mono:wght@400;500&display=swap" rel="stylesheet">
  <link rel="stylesheet" href="/style.css">
  <script src="https://unpkg.com/htmx.org@2.0.4"></script>
  <script src="/confirm.js"></script>
  <script src="/local-time.js"></script>
</head>
<body>
  <!--
    Section is derived from activePage so existing pages don't have to opt
    in to the new sub-nav. Keep the lists below in sync when adding pages.
  -->
  
  <nav id="main-nav">
    <a href="/" class="brand">
      <span class="mark">G</span>
      greenflagged
    </a>
    <button class="nav-toggle" onclick="document.getElementById('main-nav').classList.toggle('menu-open')" aria-label="Toggle menu">&#9776;</button>
    
    <span class="spacer"></span>
    
    <a href="/login" class="auth-link">Login</a>
  </nav>
  <nav id="sub-nav" class="sub-nav">
    
      <a href="/packages" class="active">All</a>
      <a href="/packages/stale">Stale</a>
      <a href="/packages/provenance">Provenance</a>
      <a href="/packages/scopes">Scopes</a>
      <a href="/incidents">Detected</a>
    
    
    
  </nav>
  
  <div class="container"><main>
  
  <p class="text-sm mb-1"><a href="/" class="link">&larr; Home</a></p>

  <div class="sticky-bar" id="sticky-bar">
    <span class="sticky-name">@downforce/std.css</span>
    <span class="sticky-stat">No license</span>
    <span class="sticky-stat">0 versions</span>
    
    
    
  </div>

  <h1>@downforce/std.css</h1>

  <div class="flex-between">
    <div class="link-bar">
      <a href="https://www.npmjs.com/package/@downforce/std.css" target="_blank" rel="noopener">npm</a>
      
      
    </div>
    
  </div>

  

  <div class="stats" style="margin-top: 1rem;">
    <div class="stat">
      <div class="value">0</div>
      <div class="label">Versions</div>
    </div>
    <div class="stat">
      <div class="value">—</div>
      <div class="label">License</div>
    </div>
    <div class="stat">
      <div class="value">No</div>
      <div class="label">Install Scripts</div>
    </div>
    <div class="stat warn">
      <div class="value">Missing</div>
      <div class="label">Provenance</div>
    </div>
  </div>

  <!-- Provenance status — always shown so reviewers can push the angle.
       SLSA attestations are the strongest supply-chain integrity signal;
       only ~12% of npm packages have them. -->
  <div class="card">
    <h2>Supply chain provenance</h2>
    <p class="text-sm text-muted" style="margin-bottom: 0.5rem;">
      Status for the latest visible version.
    </p>
    <div style="display: flex; flex-wrap: wrap; gap: 0.5rem;">
      <span class="badge badge-rejected">No SLSA provenance</span>
      <span class="badge badge-needs_review">Unsigned tarball</span>
      <span class="badge badge-needs_review">No source commit</span>
    </div>
    <p class="text-sm text-muted" style="margin-top: 0.5rem;">
      Without SLSA provenance there is no cryptographic link between this
      tarball and the public source — the axios compromise (March 2026)
      relied on exactly this gap.
    </p>
  </div>

  <!-- Author Trust -->
  

  <!-- Fallback maintainers -->
  

  <!-- Keywords -->
  

  
  

  <!-- Versions -->
  <div class="card">
    <div class="flex-between">
      <h2>Versions <span class="text-muted text-sm">(showing 0 of 0)</span></h2>
      <div style="display: flex; gap: 0.3rem;">
        
        
        
      </div>
    </div>

    <!-- Bulk action bar -->
    

    <table>
      <thead>
        <tr>
          
          <th>Version</th>
          
          
          <th>Deps</th>
          
          
          <th>Published</th>
        </tr>
      </thead>
      <tbody>
        
      </tbody>
    </table>

    

    
  </div>

  <!-- Public per-version findings: only shown for versions with vuln/malware,
       provenance signals, or HIGH/CRITICAL findings from any analyzer.
       Suppressed for admins — the version table's "Findings" count plus the
       per-version page (/packages/{name}/v/{version}) carry the full detail,
       so the list page stays light and doesn't ship every version's
       sast_results blob. The auth check is per-render, not per-row, so it
       wraps the loop instead of riding on each card. -->
  
    
  

  <script>
    document.querySelectorAll('.linkify').forEach(function(el) {
      el.innerHTML = el.textContent.replace(
        /(https?:\/\/[^\s<]+)/g,
        '<a href="$1" target="_blank" rel="noopener" class="link">$1</a>'
      );
    });
  </script>
</main></div>
</body>
</html>
