← Home

@pagopa/io-app-design-system

The library defining the core components of the design system of @pagopa/io-app

4
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

pagopa-botpasqualedevitapp-psdiego.lagosmorales

Keywords

react-nativeiosandroid

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:markdown-it AI (dependencies): markdown-it is a well-established, widely-used library; stable false positive for this package. ai
phantom-deps phantom-dep:auto-changelog AI (phantom-deps): auto-changelog is used in release-it config scripts, not imported in source; stable false positive for this package. ai
phantom-deps phantom-dep:react-native-easing-gradient AI (phantom-deps): Platform-specific binary package; not directly imported in JS but used at runtime; stable false positive. ai

Versions (showing 4 of 4)

Version Deps Published
7.2.0 10 / 40
7.1.1 10 / 40
7.1.0 10 / 40
7.0.2 10 / 41

v7.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.