@theme-ui/preset-deep
Theme UI includes `@theme-ui/preset-deep` which can be used as an example or starting point for extending your own themes.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Long-stable maintainer transition within theme-ui org, not recent. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Publisher change is 2040 days stale, inconsistent with takeover. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy explained by mature, low-churn package, no material diff. | ai |
Versions (showing 51 of 52)
| Version | Deps | Published |
|---|---|---|
| 0.17.4 | 0 / 1 | |
| 0.17.2 | 0 / 1 | |
| 0.17.1 | 0 / 1 | |
| 0.17.0 | 0 / 1 | |
| 0.16.2 | 0 / 1 | |
| 0.16.1 | 0 / 1 | |
| 0.16.0 | 0 / 1 | |
| 0.15.7 | 0 / 0 | |
| 0.15.5 | 0 / 0 | |
| 0.15.4 | 0 / 0 | |
| 0.15.3 | 0 / 0 | |
| 0.15.1 | 0 / 0 | |
| 0.15.0 | 0 / 0 | |
| 0.14.7 | 0 / 0 | |
| 0.14.6 | 0 / 0 | |
| 0.14.5 | 0 / 0 | |
| 0.14.4 | 0 / 0 | |
| 0.14.3 | 0 / 0 | |
| 0.14.2 | 0 / 0 | |
| 0.14.1 | 0 / 0 | |
| 0.14.0 | 0 / 0 | |
| 0.13.1 | 0 / 0 | |
| 0.13.0 | 0 / 0 | |
| 0.12.1 | 0 / 0 | |
| 0.12.0 | 0 / 0 | |
| 0.11.3 | 0 / 0 | |
| 0.11.2 | 0 / 0 | |
| 0.11.1 | 0 / 0 | |
| 0.11.0 | 0 / 0 | |
| 0.10.1 | 0 / 0 | |
| 0.10.0 | 0 / 0 | |
| 0.9.1 | 0 / 0 | |
| 0.9.0 | 0 / 0 | |
| 0.8.4 | 0 / 0 | |
| 0.8.3 | 0 / 0 | |
| 0.8.2 | 0 / 0 | |
| 0.8.1 | 0 / 0 | |
| 0.8.0 | 0 / 0 | |
| 0.7.5 | 0 / 0 | |
| 0.7.4 | 0 / 0 | |
| 0.7.3 | 0 / 0 | |
| 0.7.2 | 0 / 0 | |
| 0.7.1 | 0 / 0 | |
| 0.7.0 | 0 / 0 | |
| 0.6.0 | 0 / 0 | |
| 0.3.5 | 0 / 0 | |
| 0.3.4 | 0 / 0 | |
| 0.3.0 | 0 / 0 | |
| 0.2.40 | 0 / 0 | |
| 0.2.29 | 0 / 0 | |
| 0.2.25 | 0 / 0 |
v0.17.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.16.2
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2024-02-19. It has since remained available on npm for 885 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.16.1
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2023-08-14. It has since remained available on npm for 1074 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.16.0
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2023-06-15. It has since remained available on npm for 1134 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.7
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2023-03-30. It has since remained available on npm for 1211 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.5
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2023-02-07. It has since remained available on npm for 1262 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.4
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-11-10. It has since remained available on npm for 1351 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.3
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-10-17. It has since remained available on npm for 1375 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.1
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-09-26. It has since remained available on npm for 1396 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.0
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-09-26. It has since remained available on npm for 1396 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.7
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-07-28. It has since remained available on npm for 1456 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.6
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-06-15. It has since remained available on npm for 1499 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.5
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-04-30. It has since remained available on npm for 1545 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.4
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-04-23. It has since remained available on npm for 1552 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.3
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-04-21. It has since remained available on npm for 1554 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.2
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-03-31. It has since remained available on npm for 1575 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.1
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-03-22. It has since remained available on npm for 1584 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.0
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-03-21. It has since remained available on npm for 1585 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.1
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2022-01-05. It has since remained available on npm for 1661 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.13.0
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-12-27. It has since remained available on npm for 1669 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.1
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-11-22. It has since remained available on npm for 1704 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.0
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-10-28. It has since remained available on npm for 1730 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.3
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-09-24. It has since remained available on npm for 1763 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.2
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-09-08. It has since remained available on npm for 1780 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.1
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-08-25. It has since remained available on npm for 1793 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.0
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-08-25. It has since remained available on npm for 1793 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.1
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-06-19. It has since remained available on npm for 1860 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-06-19. It has since remained available on npm for 1860 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.1
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-05-26. It has since remained available on npm for 1884 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.0
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-05-25. It has since remained available on npm for 1885 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.4
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-05-06. It has since remained available on npm for 1904 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.3
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-05-05. It has since remained available on npm for 1905 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.2
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-05-05. It has since remained available on npm for 1905 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.1
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-05-05. It has since remained available on npm for 1905 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-05-05. It has since remained available on npm for 1906 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.5
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-04-28. It has since remained available on npm for 1912 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.4
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-04-27. It has since remained available on npm for 1913 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.3
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-04-21. It has since remained available on npm for 1919 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.2
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-04-19. It has since remained available on npm for 1921 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.1
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-04-19. It has since remained available on npm for 1921 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-04-15. It has since remained available on npm for 1925 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2021-03-22. It has since remained available on npm for 1950 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.5
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2020-12-21. It has since remained available on npm for 2040 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.4
2 findingsThis version was published by a different npm account (hasparus) than the most recent previously approved version (jxnblk) on 2020-11-20. It has since remained available on npm for 2071 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.