← Home

@ni/nimble-components

13
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ni-webapps-opsmilanraj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/d3-zoom AI (phantom-deps): TypeScript type package; loaded by convention, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:@types/d3-array AI (phantom-deps): TypeScript type package; loaded by convention, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:@types/d3-scale AI (phantom-deps): TypeScript type package; loaded by convention, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:@types/d3-random AI (phantom-deps): TypeScript type package; loaded by convention, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:@types/markdown-it AI (phantom-deps): TypeScript type package; loaded by convention, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:@types/d3-selection AI (phantom-deps): TypeScript type package; loaded by convention, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:d3-random AI (phantom-deps): d3-random is a runtime dep used in chart/visualization code; phantom-dep heuristic misfires here. ai

Versions (showing 13 of 13)

Version Deps Published
35.10.0 36 / 26
35.9.3 36 / 26
35.9.2 36 / 26
35.9.1 36 / 26
35.9.0 36 / 26
35.8.0 36 / 26
35.7.1 36 / 26
35.7.0 36 / 26
35.6.1 36 / 26
35.6.0 36 / 26
35.5.8 36 / 26
35.5.7 36 / 26
35.5.6 36 / 26

v35.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.9.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.9.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.9.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.5.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.5.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.5.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.