@hmcts/ccd-case-ui-toolkit
Case UI Toolkit
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@angular-material-components/datetime-picker | AI (dependencies): Angular Material datetime picker; consistent with Angular Material usage. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Mass dep addition reflects Angular major version migration; all deps are recognizable Angular/govuk ecosystem packages. | ai | |
| dependencies | unvetted-dep:ngx-chips | AI (dependencies): Established Angular tag-input library; stable for this package. | ai | |
| dependencies | unvetted-dep:@edium/fsm | AI (dependencies): FSM library used by HMCTS toolkit; consistent with prior usage pattern. | ai | |
| dependencies | unvetted-dep:@ngrx/store | AI (dependencies): Well-known Angular state management library from the NgRx org. | ai | |
| dependencies | unvetted-dep:@ngrx/effects | AI (dependencies): Well-known Angular effects library from the NgRx org. | ai | |
| dependencies | unvetted-dep:ngx-pagination | AI (dependencies): Established Angular pagination library. | ai | |
| dependencies | unvetted-dep:rx-polling-hmcts | AI (dependencies): HMCTS-maintained polling library; consistent with package ecosystem. | ai | |
| dependencies | unvetted-dep:@hmcts/media-viewer | AI (dependencies): HMCTS-maintained sibling package; consistent with package ecosystem. | ai | |
| dependencies | unvetted-dep:rpx-xui-translation | AI (dependencies): HMCTS/RPX translation library; consistent with package ecosystem. | ai | |
| dependencies | unvetted-dep:@hmcts/ccpay-web-component | AI (dependencies): HMCTS-maintained sibling package; consistent with package ecosystem. | ai | |
| dependencies | unvetted-dep:@nicky-lenaers/ngx-scroll-to | AI (dependencies): Established Angular scroll library; stable for this package. | ai | |
| dependencies | unvetted-dep:@angular-material-components/moment-adapter | AI (dependencies): Angular Material datetime adapter; consistent with Angular Material usage. | ai | |
| provenance | slsa-provenance | AI (provenance): CI/CD published with Sigstore SLSA attestation; stable supply chain signal for this package. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 7.3.54 | 1 / 0 | |
| 7.3.53 | 1 / 0 | |
| 7.3.52 | 1 / 0 | |
| 7.3.51 | 45 / 0 | |
| 7.3.50 | 45 / 0 | |
| 7.3.49 | 1 / 0 | |
| 7.3.48 | 1 / 0 | |
| 7.3.47 | 1 / 0 | |
| 7.3.46 | 1 / 0 | |
| 7.3.45 | 1 / 0 | |
| 7.3.44 | 1 / 0 |
v7.3.54
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.53
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.50
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.49
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.48
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.47
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.3.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.