@jobber/components
Atlantis is a component library designed and maintained by [Jobber](https://getjobber.com).
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:ts-xor | AI (dependencies): ts-xor is a tiny TypeScript XOR type utility; no security risk for this component library. | ai | |
| dependencies | unvetted-dep:react-countdown | AI (dependencies): react-countdown is a standard React countdown component; no security risk for this component library. | ai | |
| phantom-deps | phantom-dep:@types/lodash | AI (phantom-deps): @types/* packages are framework-scoped; not directly imported by convention. | ai | |
| phantom-deps | phantom-dep:react-markdown | AI (phantom-deps): Referenced in config/storybook files; stable false positive for this component library. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit TypeScript runtime dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/react-router | AI (phantom-deps): @types/* packages are framework-scoped; not directly imported by convention. | ai | |
| phantom-deps | phantom-dep:@types/react-router-dom | AI (phantom-deps): @types/* packages are framework-scoped; not directly imported by convention. | ai | |
| phantom-deps | phantom-dep:react-countdown | AI (phantom-deps): Used in Countdown component; referenced in config files; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/color | AI (phantom-deps): @types/* packages are framework-scoped; not directly imported by convention. | ai |
Versions (showing 51 of 127)
| Version | Deps | Published |
|---|---|---|
| 8.29.0 | 23 / 35 | |
| 8.28.2 | 23 / 35 | |
| 8.28.1 | 23 / 35 | |
| 8.28.0 | 23 / 35 | |
| 8.27.2 | 23 / 35 | |
| 8.27.1 | 23 / 35 | |
| 8.27.0 | 23 / 35 | |
| 8.26.3 | 23 / 35 | |
| 8.26.2 | 23 / 35 | |
| 8.26.1 | 23 / 35 | |
| 8.26.0 | 23 / 35 | |
| 8.25.2 | 23 / 35 | |
| 8.25.1 | 23 / 35 | |
| 8.25.0 | 23 / 35 | |
| 8.24.1 | 23 / 35 | |
| 8.24.0 | 23 / 35 | |
| 8.23.1 | 24 / 35 | |
| 8.23.0 | 24 / 35 | |
| 8.22.0 | 24 / 35 | |
| 8.21.1 | 24 / 35 | |
| 8.21.0 | 24 / 35 | |
| 8.20.2 | 24 / 35 | |
| 8.20.1 | 24 / 35 | |
| 8.20.0 | 24 / 35 | |
| 7.14.0 | 25 / 35 | |
| 7.13.2 | 25 / 35 | |
| 7.13.1 | 25 / 35 | |
| 7.13.0 | 25 / 35 | |
| 7.12.2 | 25 / 35 | |
| 7.12.1 | 25 / 35 | |
| 7.12.0 | 25 / 35 | |
| 7.11.3 | 25 / 35 | |
| 7.11.2 | 25 / 35 | |
| 7.11.1 | 25 / 35 | |
| 7.11.0 | 25 / 35 | |
| 7.10.0 | 25 / 35 | |
| 7.9.0 | 25 / 35 | |
| 7.8.0 | 25 / 35 | |
| 7.7.0 | 25 / 35 | |
| 7.6.0 | 25 / 35 | |
| 7.5.0 | 25 / 35 | |
| 7.4.0 | 25 / 35 | |
| 7.3.0 | 25 / 35 | |
| 7.2.0 | 25 / 35 | |
| 7.1.2 | 25 / 35 | |
| 7.1.1 | 25 / 36 | |
| 7.1.0 | 25 / 36 | |
| 7.0.0 | 25 / 35 | |
| 6.123.2 | 25 / 35 | |
| 6.123.1 | 22 / 21 | |
| 6.123.0 | 22 / 21 |
v8.29.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.28.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.28.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.27.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.27.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.26.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.26.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.26.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.25.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.25.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.24.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.23.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.21.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.20.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.20.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.20.0
2 findingsThis version was published by a different npm account than previous versions on 2026-06-26. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.