@hmcts/ccd-case-ui-toolkit
Case UI Toolkit
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): CI/CD-driven release cadence, no diff from prior approved version. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): Known implicit dependency; stable for TypeScript packages. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): CLI/config tool; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Markdown processor; stable for this package. | ai | |
| phantom-deps | phantom-dep:lz-string | AI (phantom-deps): Compression utility; stable for this package. | ai | |
| phantom-deps | phantom-dep:file-saver | AI (phantom-deps): Browser utility; stable for this package. | ai | |
| phantom-deps | phantom-dep:yargs-parser | AI (phantom-deps): CLI parser; stable for this package. | ai | |
| phantom-deps | phantom-dep:govuk-frontend | AI (phantom-deps): UI framework; stable for this package. | ai | |
| phantom-deps | phantom-dep:pegjs | AI (phantom-deps): Build/parser tool; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:rpx-xui-translation | AI (dependencies): HMCTS/RPX translation library; consistent with package ecosystem. | ai | |
| dependencies | unvetted-dep:@hmcts/ccpay-web-component | AI (dependencies): HMCTS-maintained sibling package; consistent with package ecosystem. | ai | |
| dependencies | unvetted-dep:@angular-material-components/moment-adapter | AI (dependencies): Angular Material datetime adapter; consistent with Angular Material usage. | ai | |
| dependencies | unvetted-dep:@angular-material-components/datetime-picker | AI (dependencies): Angular Material datetime picker; consistent with Angular Material usage. | ai | |
| dependencies | unvetted-dep:@nicky-lenaers/ngx-scroll-to | AI (dependencies): Established Angular scroll library; stable for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Mass dep addition reflects Angular major version migration; all deps are recognizable Angular/govuk ecosystem packages. | ai | |
| dependencies | unvetted-dep:ngx-chips | AI (dependencies): Established Angular tag-input library; stable for this package. | ai | |
| dependencies | unvetted-dep:@edium/fsm | AI (dependencies): FSM library used by HMCTS toolkit; consistent with prior usage pattern. | ai | |
| dependencies | unvetted-dep:@ngrx/store | AI (dependencies): Well-known Angular state management library from the NgRx org. | ai | |
| dependencies | unvetted-dep:@ngrx/effects | AI (dependencies): Well-known Angular effects library from the NgRx org. | ai | |
| dependencies | unvetted-dep:ngx-pagination | AI (dependencies): Established Angular pagination library. | ai | |
| dependencies | unvetted-dep:rx-polling-hmcts | AI (dependencies): HMCTS-maintained polling library; consistent with package ecosystem. | ai | |
| dependencies | unvetted-dep:@hmcts/media-viewer | AI (dependencies): HMCTS-maintained sibling package; consistent with package ecosystem. | ai | |
| provenance | slsa-provenance | AI (provenance): CI/CD published with Sigstore SLSA attestation; stable supply chain signal for this package. | ai |
Versions (showing 46 of 46)
| Version | Deps | Published |
|---|---|---|
| 7.3.75 | 11 / 0 | |
| 7.3.71 | 11 / 0 | |
| 7.3.68 | 11 / 0 | |
| 7.3.67 | 11 / 0 | |
| 7.3.65 | 11 / 0 | |
| 7.3.64 | 1 / 0 | |
| 7.3.63 | 1 / 0 | |
| 7.3.62 | 1 / 0 | |
| 7.3.61 | 1 / 0 | |
| 7.3.60 | 1 / 0 | |
| 7.3.59 | 1 / 0 | |
| 7.3.58 | 1 / 0 | |
| 7.3.57 | 1 / 0 | |
| 7.3.56 | 1 / 0 | |
| 7.3.55 | 1 / 0 | |
| 7.3.54 | 1 / 0 | |
| 7.3.53 | 1 / 0 | |
| 7.3.52 | 1 / 0 | |
| 7.3.51 | 45 / 0 | |
| 7.3.50 | 45 / 0 | |
| 7.3.49 | 1 / 0 | |
| 7.3.48 | 1 / 0 | |
| 7.3.47 | 1 / 0 | |
| 7.3.46 | 1 / 0 | |
| 7.3.45 | 1 / 0 | |
| 7.3.44 | 1 / 0 | |
| 7.3.43 | 1 / 0 | |
| 7.3.42 | 1 / 0 | |
| 7.3.41 | 1 / 0 | |
| 7.3.40 | 1 / 0 | |
| 7.3.39 | 1 / 0 | |
| 7.3.38 | 1 / 0 | |
| 7.3.37 | 1 / 0 | |
| 7.3.36 | 1 / 0 | |
| 7.3.35 | 1 / 0 | |
| 7.3.34 | 1 / 0 | |
| 7.3.33 | 1 / 0 | |
| 7.3.3 | 1 / 0 | |
| 7.3.2 | 1 / 0 | |
| 7.3.1 | 1 / 0 | |
| 7.3.0 | 1 / 0 | |
| 7.2.59 | 1 / 0 | |
| 7.2.58 | 1 / 0 | |
| 7.2.57 | 1 / 0 | |
| 7.2.56 | 1 / 0 | |
| 7.2.55 | 1 / 0 |
v7.3.75
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.71
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.42
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.37
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.36
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.35
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.33
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (jenkins-reform-hmcts) on 2026-02-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v7.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.2.59
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.2.58
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.2.57
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.2.56
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.2.55
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.