@jobber/components
Atlantis is a component library designed and maintained by [Jobber](https://getjobber.com).
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:ts-xor | AI (dependencies): ts-xor is a tiny TypeScript XOR type utility; no security risk for this component library. | ai | |
| dependencies | unvetted-dep:react-countdown | AI (dependencies): react-countdown is a standard React countdown component; no security risk for this component library. | ai | |
| phantom-deps | phantom-dep:@types/lodash | AI (phantom-deps): @types/* packages are framework-scoped; not directly imported by convention. | ai | |
| phantom-deps | phantom-dep:react-markdown | AI (phantom-deps): Referenced in config/storybook files; stable false positive for this component library. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit TypeScript runtime dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/react-router | AI (phantom-deps): @types/* packages are framework-scoped; not directly imported by convention. | ai | |
| phantom-deps | phantom-dep:@types/react-router-dom | AI (phantom-deps): @types/* packages are framework-scoped; not directly imported by convention. | ai | |
| phantom-deps | phantom-dep:react-countdown | AI (phantom-deps): Used in Countdown component; referenced in config files; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/color | AI (phantom-deps): @types/* packages are framework-scoped; not directly imported by convention. | ai |
Versions (showing 27 of 128)
| Version | Deps | Published |
|---|---|---|
| 6.109.2 | 21 / 21 | |
| 6.109.1 | 21 / 21 | |
| 6.109.0 | 21 / 21 | |
| 6.108.0 | 21 / 21 | |
| 6.107.2 | 21 / 21 | |
| 6.107.1 | 21 / 21 | |
| 6.107.0 | 21 / 21 | |
| 6.106.4 | 21 / 21 | |
| 6.106.3 | 21 / 21 | |
| 6.106.2 | 21 / 21 | |
| 6.106.1 | 21 / 21 | |
| 6.106.0 | 21 / 21 | |
| 6.105.5 | 21 / 21 | |
| 6.105.4 | 21 / 21 | |
| 6.105.3 | 21 / 21 | |
| 6.105.2 | 21 / 21 | |
| 6.105.1 | 21 / 21 | |
| 6.105.0 | 21 / 21 | |
| 6.104.1 | 21 / 21 | |
| 6.104.0 | 21 / 21 | |
| 6.103.6 | 21 / 21 | |
| 6.103.5 | 21 / 21 | |
| 6.103.4 | 21 / 21 | |
| 6.103.3 | 21 / 21 | |
| 6.103.2 | 21 / 21 | |
| 6.103.1 | 21 / 21 | |
| 6.103.0 | 21 / 21 |
v6.109.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.109.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.109.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.108.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.107.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.107.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.107.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.106.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.106.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.106.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.106.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.106.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.105.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.105.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.105.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.105.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.105.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.105.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.104.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.104.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.103.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.103.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.103.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.103.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.103.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.103.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.103.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.