@times-components/article-in-depth
In Depth Article Template
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Long-established Times Components monorepo; lack of Sigstore provenance is consistent across all versions and not a security concern here. | ai | |
| phantom-deps | phantom-dep:@times-components/ad | AI (phantom-deps): Same-org sibling dep in a monorepo; phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:@times-components/user-state | AI (phantom-deps): Same-org sibling dep in a monorepo; phantom-dep heuristic is a stable false positive here. | ai |
Versions (showing 100 of 683)
| Version | Deps | Published |
|---|---|---|
| 3.100.18 | 15 / 19 | |
| 3.100.17 | 15 / 19 | |
| 3.100.16 | 15 / 19 | |
| 3.100.15 | 15 / 19 | |
| 3.100.14 | 15 / 19 | |
| 3.100.13 | 15 / 19 | |
| 3.100.12 | 15 / 19 | |
| 3.100.11 | 15 / 19 | |
| 3.100.10 | 15 / 19 | |
| 3.100.9 | 15 / 19 | |
| 3.100.8 | 15 / 19 | |
| 3.100.7 | 15 / 19 | |
| 3.100.6 | 15 / 19 | |
| 3.100.5 | 15 / 19 | |
| 3.100.4 | 15 / 19 | |
| 3.100.3 | 15 / 19 | |
| 3.100.2 | 15 / 19 | |
| 3.100.1 | 15 / 19 | |
| 3.100.0 | 15 / 19 | |
| 3.99.0 | 15 / 19 | |
| 3.98.5 | 15 / 19 | |
| 3.98.4 | 15 / 19 | |
| 3.98.3 | 15 / 19 | |
| 3.98.2 | 15 / 19 | |
| 3.98.1 | 15 / 19 | |
| 3.98.0 | 15 / 19 | |
| 3.97.5 | 15 / 19 | |
| 3.97.3 | 15 / 19 | |
| 3.97.2 | 15 / 19 | |
| 3.97.1 | 15 / 19 | |
| 3.97.0 | 15 / 19 | |
| 3.96.0 | 15 / 19 | |
| 3.95.15 | 15 / 19 | |
| 3.95.14 | 15 / 19 | |
| 3.95.13 | 15 / 19 | |
| 3.95.12 | 15 / 19 | |
| 3.95.11 | 15 / 19 | |
| 3.95.10 | 15 / 19 | |
| 3.95.9 | 15 / 19 | |
| 3.95.8 | 15 / 19 | |
| 3.95.7 | 15 / 19 | |
| 3.95.6 | 15 / 19 | |
| 3.95.5 | 15 / 19 | |
| 3.95.4 | 15 / 19 | |
| 3.95.3 | 15 / 19 | |
| 3.95.2 | 15 / 19 | |
| 3.95.1 | 15 / 19 | |
| 3.95.0 | 15 / 19 | |
| 3.94.19 | 15 / 19 | |
| 3.94.18 | 15 / 19 | |
| 3.94.17 | 15 / 19 | |
| 3.94.16 | 15 / 19 | |
| 3.94.15 | 15 / 19 | |
| 3.94.14 | 15 / 19 | |
| 3.94.13 | 15 / 19 | |
| 3.94.12 | 15 / 19 | |
| 3.94.11 | 15 / 19 | |
| 3.94.10 | 15 / 19 | |
| 3.94.9 | 15 / 19 | |
| 3.94.8 | 15 / 19 | |
| 3.94.7 | 15 / 19 | |
| 3.94.6 | 15 / 19 | |
| 3.94.5 | 15 / 19 | |
| 3.94.4 | 15 / 19 | |
| 3.94.3 | 15 / 19 | |
| 3.94.2 | 15 / 19 | |
| 3.94.1 | 15 / 19 | |
| 3.94.0 | 15 / 19 | |
| 3.93.3 | 15 / 19 | |
| 3.93.2 | 15 / 19 | |
| 3.93.1 | 15 / 19 | |
| 3.93.0 | 15 / 19 | |
| 3.92.6 | 15 / 19 | |
| 3.92.5 | 15 / 19 | |
| 3.92.4 | 15 / 19 | |
| 3.92.3 | 15 / 19 | |
| 3.92.2 | 15 / 19 | |
| 3.92.1 | 15 / 19 | |
| 3.92.0 | 15 / 19 | |
| 3.91.0 | 15 / 19 | |
| 3.90.13 | 15 / 19 | |
| 3.90.12 | 15 / 19 | |
| 3.90.11 | 15 / 19 | |
| 3.90.10 | 15 / 19 | |
| 3.90.9 | 15 / 19 | |
| 3.90.8 | 15 / 19 | |
| 3.90.7 | 15 / 19 | |
| 3.90.6 | 15 / 19 | |
| 3.90.4 | 15 / 19 | |
| 3.90.3 | 15 / 19 | |
| 3.90.1 | 15 / 19 | |
| 3.90.0 | 15 / 19 | |
| 3.89.12 | 15 / 19 | |
| 3.89.11 | 15 / 19 | |
| 3.89.10 | 15 / 19 | |
| 3.89.9 | 15 / 19 | |
| 3.89.8 | 15 / 19 | |
| 3.89.7 | 15 / 19 | |
| 3.89.6 | 15 / 19 | |
| 3.89.5 | 15 / 19 |
v3.98.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.98.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.98.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.97.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.97.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.97.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.97.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.97.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.96.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.95.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.94.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.93.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.93.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.93.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.93.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.92.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.92.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.92.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.92.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.92.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.92.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.92.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.91.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.90.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.89.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.89.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.89.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.89.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.89.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.89.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.89.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.89.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.