@fluid-topics/ft-icon
Typography components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): rtellier is an established publisher (949 approved) within the Antidot/Fluid Topics org; transition appears legitimate. | ai | |
| dependencies | unvetted-dep:@awesome.me/kit-f60314a0e3 | AI (dependencies): Font Awesome Pro private kit dependency; standard pattern for FA Pro users, stable across versions of this package. | ai |
Versions (showing 51 of 72)
| Version | Deps | Published |
|---|---|---|
| 2.1.15 | 3 / 0 | |
| 2.1.14 | 3 / 0 | |
| 2.1.12 | 3 / 0 | |
| 2.1.11 | 3 / 0 | |
| 2.1.10 | 3 / 0 | |
| 2.1.9 | 3 / 0 | |
| 2.1.8 | 3 / 0 | |
| 2.1.7 | 3 / 0 | |
| 2.1.6 | 3 / 0 | |
| 2.1.5 | 3 / 0 | |
| 2.1.4 | 3 / 0 | |
| 2.1.3 | 3 / 0 | |
| 2.1.2 | 3 / 0 | |
| 2.1.1 | 3 / 0 | |
| 2.1.0 | 3 / 0 | |
| 2.0.24 | 3 / 0 | |
| 2.0.23 | 3 / 0 | |
| 2.0.22 | 3 / 0 | |
| 2.0.16 | 4 / 0 | |
| 2.0.12 | 4 / 0 | |
| 2.0.11 | 4 / 0 | |
| 1.3.59 | 2 / 0 | |
| 1.3.58 | 2 / 0 | |
| 1.3.57 | 2 / 0 | |
| 1.3.56 | 2 / 0 | |
| 1.3.55 | 2 / 0 | |
| 1.3.54 | 2 / 0 | |
| 1.3.53 | 2 / 0 | |
| 1.3.52 | 2 / 0 | |
| 1.3.51 | 2 / 0 | |
| 1.3.50 | 2 / 0 | |
| 1.3.49 | 2 / 0 | |
| 1.3.48 | 2 / 0 | |
| 1.3.47 | 2 / 0 | |
| 1.3.46 | 2 / 0 | |
| 1.3.45 | 2 / 0 | |
| 1.3.44 | 2 / 0 | |
| 1.3.43 | 2 / 0 | |
| 1.3.42 | 2 / 0 | |
| 1.3.41 | 2 / 0 | |
| 1.3.40 | 2 / 0 | |
| 1.3.39 | 2 / 0 | |
| 1.3.38 | 2 / 0 | |
| 1.3.37 | 2 / 0 | |
| 1.3.36 | 2 / 0 | |
| 1.3.35 | 2 / 0 | |
| 1.3.34 | 2 / 0 | |
| 1.3.33 | 2 / 0 | |
| 1.3.32 | 2 / 0 | |
| 1.3.31 | 2 / 0 | |
| 1.3.30 | 2 / 0 |
v2.1.15
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rtellier) than the most recent previously approved version (antidot) on 2026-07-27, but rtellier is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.1.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.