← Home

@guardian/stand

_Find what you need on the (news)stand!_

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

guardian-developerscoldlinkakash1810reettaandrew.howe-elysndrsashcorrguardian

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/types/components/intended-audience-signifier/sandbox.d.ts AI (source-diff): Long lines are JSX sandbox code embedded as string literals in a .d.ts declaration file — not obfuscation. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom is declared as both a dependency and peer dependency; phantom-dep is a false positive here. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Guardian monorepo initial publish pattern; 114 versions in registry confirms active org, not throwaway. ai
source-diff obfuscated-file:dist/types/components/menu/sandbox.d.ts AI (source-diff): Long lines are embedded JSX/CSS strings in .d.ts sandbox demo files, not obfuscated malicious code. ai
source-diff obfuscated-file:dist/types/components/icon-button/sandbox.d.ts AI (source-diff): Same pattern: readable JSX/CSS strings in sandbox .d.ts files. ai
source-diff obfuscated-file:dist/types/components/button/sandbox.d.ts AI (source-diff): Long lines are readable JSX/CSS strings embedded in .d.ts sandbox demo files, not obfuscated malware. ai
source-diff obfuscated-file:dist/types/components/icon-link-button/sandbox.d.ts AI (source-diff): Same pattern: readable JSX/CSS strings in sandbox .d.ts files. ai
source-diff obfuscated-file:dist/types/components/link-button/sandbox.d.ts AI (source-diff): Same pattern: readable JSX/CSS strings in sandbox .d.ts files. ai
source-diff obfuscated-file:dist/types/components/text-area/sandbox.d.ts AI (source-diff): Same pattern: embedded sandbox code strings in TypeScript declaration files, not obfuscation. ai
source-diff obfuscated-file:dist/types/components/alert-banner/sandbox.d.ts AI (source-diff): Same pattern: embedded sandbox code strings in TypeScript declaration files, not obfuscation. ai
source-diff obfuscated-file:dist/types/components/checkbox/CheckboxSandbox.d.ts AI (source-diff): Long lines are embedded JSX/CSS string literals in .d.ts sandbox files, not obfuscation. ai
source-diff obfuscated-file:dist/types/components/radio-group/sandbox.d.ts AI (source-diff): Long lines are embedded JSX/CSS string literals in .d.ts sandbox files, not obfuscation. ai
source-diff obfuscated-file:dist/types/components/checkbox/CheckboxGroupSandbox.d.ts AI (source-diff): Long lines are embedded JSX/CSS string literals in .d.ts sandbox files, not obfuscation. ai
typosquat typosquat.levenshtein:zustand AI (typosquat): Legitimate @guardian org design system package; scoped namespace makes typosquatting implausible. ai

Versions (showing 51 of 63)

View all versions
Version Deps Published
0.0.63 0 / 52
0.0.62 0 / 52
0.0.61 0 / 52
0.0.60 0 / 52
0.0.59 0 / 52
0.0.58 0 / 52
0.0.57 0 / 52
0.0.56 0 / 52
0.0.55 0 / 52
0.0.54 0 / 52
0.0.53 0 / 52
0.0.52 0 / 52
0.0.51 0 / 52
0.0.50 0 / 52
0.0.49 0 / 52
0.0.48 0 / 52
0.0.47 0 / 52
0.0.46 0 / 52
0.0.45 0 / 51
0.0.44 0 / 51
0.0.43 0 / 51
0.0.42 0 / 51
0.0.41 0 / 51
0.0.40 0 / 54
0.0.39 0 / 54
0.0.38 0 / 54
0.0.37 0 / 54
0.0.36 0 / 54
0.0.35 0 / 54
0.0.34 0 / 54
0.0.33 0 / 54
0.0.32 0 / 52
0.0.31 0 / 51
0.0.30 0 / 51
0.0.29 0 / 51
0.0.28 0 / 51
0.0.27 0 / 51
0.0.26 0 / 51
0.0.25 0 / 51
0.0.24 0 / 51
0.0.23 0 / 51
0.0.22 0 / 51
0.0.21 0 / 51
0.0.20 0 / 52
0.0.19 0 / 52
0.0.18 0 / 52
0.0.17 0 / 52
0.0.16 0 / 53
0.0.15 0 / 52
0.0.14 0 / 51
0.0.13 0 / 51

v0.0.63

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.62

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.61

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.60

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.59

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.58

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.57

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.56

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.55

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.54

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.