@khanacademy/wonder-blocks-icon-button
27
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
khanacademy
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Khan Academy migrated to GitHub Actions publishing with SLSA attestation; publisher change is legitimate and expected going forward. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy reflects CI/CD pipeline migration, not account takeover; SLSA provenance confirms legitimate publish. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established KA design system package; empty description field is a cosmetic issue, not a risk signal. | ai | |
| phantom-deps | phantom-dep:@khanacademy/wonder-blocks-theming | AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 11.4.4 | 7 / 1 | |
| 11.4.3 | 7 / 1 | |
| 11.4.2 | 7 / 1 | |
| 11.4.1 | 7 / 1 | |
| 11.4.0 | 7 / 1 | |
| 11.3.5 | 7 / 1 | |
| 11.3.4 | 7 / 1 | |
| 11.3.3 | 7 / 1 | |
| 11.3.2 | 7 / 1 | |
| 11.3.1 | 7 / 1 | |
| 11.3.0 | 7 / 1 | |
| 11.2.4 | 7 / 1 | |
| 11.2.3 | 7 / 1 | |
| 11.2.2 | 7 / 1 | |
| 11.2.1 | 7 / 1 | |
| 11.2.0 | 7 / 1 | |
| 11.1.6 | 7 / 1 | |
| 11.1.5 | 7 / 1 | |
| 11.1.4 | 7 / 1 | |
| 11.1.3 | 7 / 1 | |
| 11.1.2 | 7 / 1 | |
| 11.1.1 | 7 / 1 | |
| 11.1.0 | 7 / 1 | |
| 11.0.1 | 7 / 1 | |
| 11.0.0 | 7 / 1 | |
| 10.5.7 | 7 / 1 | |
| 10.5.6 | 7 / 1 |
v11.4.4
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.4.3
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.4.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.4.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.