← Home

@hmcts/ccd-case-ui-toolkit

Case UI Toolkit

46
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

timja-hmctstimjajenkins-reform-hmctsplayfair0319thomast1906hmctsnpm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern rapid-publish AI (publish-pattern): CI/CD-driven release cadence, no diff from prior approved version. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): Known implicit dependency; stable for TypeScript packages. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): CLI/config tool; stable pattern for this package. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Markdown processor; stable for this package. ai
phantom-deps phantom-dep:lz-string AI (phantom-deps): Compression utility; stable for this package. ai
phantom-deps phantom-dep:file-saver AI (phantom-deps): Browser utility; stable for this package. ai
phantom-deps phantom-dep:yargs-parser AI (phantom-deps): CLI parser; stable for this package. ai
phantom-deps phantom-dep:govuk-frontend AI (phantom-deps): UI framework; stable for this package. ai
phantom-deps phantom-dep:pegjs AI (phantom-deps): Build/parser tool; stable pattern for this package. ai
dependencies unvetted-dep:rpx-xui-translation AI (dependencies): HMCTS/RPX translation library; consistent with package ecosystem. ai
dependencies unvetted-dep:@hmcts/ccpay-web-component AI (dependencies): HMCTS-maintained sibling package; consistent with package ecosystem. ai
dependencies unvetted-dep:@angular-material-components/moment-adapter AI (dependencies): Angular Material datetime adapter; consistent with Angular Material usage. ai
dependencies unvetted-dep:@angular-material-components/datetime-picker AI (dependencies): Angular Material datetime picker; consistent with Angular Material usage. ai
dependencies unvetted-dep:@nicky-lenaers/ngx-scroll-to AI (dependencies): Established Angular scroll library; stable for this package. ai
publish-pattern new-deps-added AI (publish-pattern): Mass dep addition reflects Angular major version migration; all deps are recognizable Angular/govuk ecosystem packages. ai
dependencies unvetted-dep:ngx-chips AI (dependencies): Established Angular tag-input library; stable for this package. ai
dependencies unvetted-dep:@edium/fsm AI (dependencies): FSM library used by HMCTS toolkit; consistent with prior usage pattern. ai
dependencies unvetted-dep:@ngrx/store AI (dependencies): Well-known Angular state management library from the NgRx org. ai
dependencies unvetted-dep:@ngrx/effects AI (dependencies): Well-known Angular effects library from the NgRx org. ai
dependencies unvetted-dep:ngx-pagination AI (dependencies): Established Angular pagination library. ai
dependencies unvetted-dep:rx-polling-hmcts AI (dependencies): HMCTS-maintained polling library; consistent with package ecosystem. ai
dependencies unvetted-dep:@hmcts/media-viewer AI (dependencies): HMCTS-maintained sibling package; consistent with package ecosystem. ai
provenance slsa-provenance AI (provenance): CI/CD published with Sigstore SLSA attestation; stable supply chain signal for this package. ai

Versions (showing 46 of 46)

Version Deps Published
7.3.75 11 / 0
7.3.71 11 / 0
7.3.68 11 / 0
7.3.67 11 / 0
7.3.65 11 / 0
7.3.64 1 / 0
7.3.63 1 / 0
7.3.62 1 / 0
7.3.61 1 / 0
7.3.60 1 / 0
7.3.59 1 / 0
7.3.58 1 / 0
7.3.57 1 / 0
7.3.56 1 / 0
7.3.55 1 / 0
7.3.54 1 / 0
7.3.53 1 / 0
7.3.52 1 / 0
7.3.51 45 / 0
7.3.50 45 / 0
7.3.49 1 / 0
7.3.48 1 / 0
7.3.47 1 / 0
7.3.46 1 / 0
7.3.45 1 / 0
7.3.44 1 / 0
7.3.43 1 / 0
7.3.42 1 / 0
7.3.41 1 / 0
7.3.40 1 / 0
7.3.39 1 / 0
7.3.38 1 / 0
7.3.37 1 / 0
7.3.36 1 / 0
7.3.35 1 / 0
7.3.34 1 / 0
7.3.33 1 / 0
7.3.3 1 / 0
7.3.2 1 / 0
7.3.1 1 / 0
7.3.0 1 / 0
7.2.59 1 / 0
7.2.58 1 / 0
7.2.57 1 / 0
7.2.56 1 / 0
7.2.55 1 / 0

v7.3.75

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.71

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.33

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: jenkins-reform-hmcts → GitHub Actions (on 2026-02-24, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (jenkins-reform-hmcts) on 2026-02-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v7.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.2.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.2.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.2.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.2.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.2.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.