← Home

@emotion/unitless

An object of css properties that don't accept values with units

16
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

emmatowntkh44emotion-release-botandarist

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher change from mitchellhamilton to emotion-release-bot is a documented, ecosystem-wide transition to automated releases for the emotion-js project. Stable for this package. ai
maintainer-change maintainer-added AI (maintainer-change): emotion-release-bot was added as part of the emotion-js project's move to automated releases. Bot has 557 approved / 0 rejected packages; this is a legitimate transition. ai
provenance missing-githead AI (provenance): Established emotion-js package with trusted publisher; missing gitHead reflects a publish environment change, not a security concern for this package. ai
provenance no-provenance AI (provenance): Lack of Sigstore provenance is a process gap, not a security risk for this well-established, trusted package. ai

Versions (showing 16 of 16)

Version Deps Published
0.10.0 0 / 0
0.9.0 0 / 0
0.8.1 0 / 0
0.8.0 0 / 0
0.7.5 0 / 0
0.7.4 0 / 0
0.7.3 0 / 0
0.7.2 0 / 0
0.7.1 0 / 0
0.7.0 0 / 0
0.6.7 0 / 0
0.6.6 0 / 0
0.6.5 0 / 0
0.6.4 0 / 0
0.6.3 0 / 0
0.6.2 0 / 0