← Home

@financial-times/cp-content-pipeline-ui

51
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

the-ftrowanmanningcheealexwilsonaendraemmalewisnotleeseraph2000hamza.samihrobertboultonrobgodfrey

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata url-dep:@financial-times/content-tree AI (npm-metadata): GitHub-pinned devDependency for an internal FT schema package; stable pattern for this org's tooling. ai
npm-metadata no-description AI (npm-metadata): Internal FT package; missing description is a cosmetic issue, not a security signal. ai
provenance no-provenance AI (provenance): Established internal FT package; lack of Sigstore provenance is consistent across all prior versions. ai
dependencies unvetted-dep:@financial-times/o-teaser AI (dependencies): Internal FT org package; consistent across versions of this package. ai
dependencies unvetted-dep:@financial-times/o-loading AI (dependencies): Internal FT org package; consistent across versions of this package. ai
dependencies unvetted-dep:@financial-times/o3-button AI (dependencies): Internal FT org package; consistent across versions of this package. ai
dependencies unvetted-dep:@financial-times/o-expander AI (dependencies): Internal FT org package; consistent across versions of this package. ai
dependencies unvetted-dep:@financial-times/o3-tooltip AI (dependencies): Internal FT org package; consistent across versions of this package. ai
dependencies unvetted-dep:@financial-times/o3-foundation AI (dependencies): Internal FT org package; consistent across versions of this package. ai
dependencies unvetted-dep:@financial-times/x-interaction AI (dependencies): Internal FT org package; consistent across versions of this package. ai
dependencies unvetted-dep:@financial-times/ft-date-format AI (dependencies): Internal FT org package; consistent across versions of this package. ai
dependencies unvetted-dep:@financial-times/o-visual-effects AI (dependencies): Internal FT org package; consistent across versions of this package. ai
dependencies unvetted-dep:@financial-times/o3-editorial-typography AI (dependencies): Internal FT org package; consistent across versions of this package. ai
dependencies unvetted-dep:@financial-times/o-labels AI (dependencies): Internal FT org package; consistent across versions of this package. ai
dependencies unvetted-dep:@financial-times/x-teaser AI (dependencies): Internal FT org package; consistent across versions of this package. ai
phantom-deps phantom-dep:@dotcom-tool-kit/npm AI (phantom-deps): Referenced in config files (dotcom-tool-kit build system), not a direct JS import — expected pattern for this package. ai
phantom-deps phantom-dep:@financial-times/o-visual-effects AI (phantom-deps): Same-org CSS/UI dependency; phantom-dep heuristic fires on non-JS imports. Stable FP for this package. ai
phantom-deps phantom-dep:@financial-times/o3-editorial-typography AI (phantom-deps): Same-org CSS/UI dependency; phantom-dep heuristic fires on non-JS imports. Stable FP for this package. ai
bogus-package bogus-package AI (bogus-package): 337-version established FT internal package; missing metadata is a known pattern for internal org packages, not spam. ai
phantom-deps phantom-dep:@financial-times/o3-button AI (phantom-deps): Same-org CSS/UI dependency; phantom-dep heuristic fires on non-JS imports. Stable FP for this package. ai
phantom-deps phantom-dep:@financial-times/o-loading AI (phantom-deps): Same-org CSS/UI dependency; phantom-dep heuristic fires on non-JS imports. Stable FP for this package. ai
phantom-deps phantom-dep:@financial-times/o-teaser AI (phantom-deps): Same-org CSS/UI dependency; phantom-dep heuristic fires on non-JS imports. Stable FP for this package. ai
phantom-deps phantom-dep:@financial-times/o3-foundation AI (phantom-deps): Same-org CSS/UI dependency; phantom-dep heuristic fires on non-JS imports. Stable FP for this package. ai
phantom-deps phantom-dep:@financial-times/o-labels AI (phantom-deps): Same-org CSS/UI dependency; phantom-dep heuristic fires on non-JS imports (SCSS/templates). Stable FP for this package. ai

Versions (showing 51 of 55)

View all versions
Version Deps Published
12.3.0 14 / 38
12.2.2 14 / 38
12.2.1 14 / 38
12.2.0 14 / 38
12.0.1 13 / 38
12.0.0 13 / 38
11.3.2 13 / 38
11.3.1 13 / 38
11.3.0 13 / 38
11.2.2 13 / 38
11.2.1 13 / 38
11.2.0 13 / 38
11.1.0 13 / 38
11.0.0 13 / 38
10.1.1 13 / 38
10.1.0 13 / 38
10.0.4 13 / 38
10.0.3 13 / 38
10.0.2 13 / 38
10.0.1 13 / 38
10.0.0 13 / 38
9.23.7 13 / 38
9.23.6 13 / 38
9.23.5 13 / 38
9.23.4 13 / 38
9.23.3 13 / 38
9.23.2 13 / 38
9.23.1 13 / 38
9.23.0 13 / 38
9.22.2 13 / 38
9.22.1 13 / 38
9.22.0 13 / 38
9.21.0 13 / 38
9.20.2 13 / 38
9.20.1 13 / 38
9.20.0 13 / 38
9.19.0 13 / 38
9.18.3 13 / 38
9.18.2 13 / 38
9.18.1 13 / 38
9.18.0 13 / 38
9.17.2 13 / 38
9.17.1 13 / 38
9.17.0 13 / 38
9.16.0 13 / 38
9.15.1 13 / 38
9.15.0 13 / 38
9.14.1 13 / 36
9.14.0 13 / 36
9.13.0 13 / 36
9.12.1 14 / 35

v12.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v12.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.3.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.23.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.23.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.23.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.23.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.23.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.23.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.23.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.23.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.22.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.21.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.20.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.20.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.18.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.18.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.18.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.17.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.17.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.17.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.15.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.15.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.14.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.14.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.