@times-components/article-paragraph
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@times-components/article-skeleton | AI (phantom-deps): Same-org sibling package in times-components monorepo; consistent pattern with other accepted phantom deps in this package. | ai | |
| phantom-deps | phantom-dep:@times-components/context | AI (phantom-deps): Same-org monorepo dep; phantom-dep false positive common in monorepo setups. | ai | |
| phantom-deps | phantom-dep:@times-components/markup-forest | AI (phantom-deps): Same-org monorepo dep; phantom-dep false positive common in monorepo setups. | ai |
Versions (showing 51 of 53)
| Version | Deps | Published |
|---|---|---|
| 1.23.0 | 5 / 17 | |
| 1.22.1 | 5 / 17 | |
| 1.22.0 | 5 / 17 | |
| 1.21.1 | 5 / 17 | |
| 1.21.0 | 5 / 17 | |
| 1.20.0 | 5 / 17 | |
| 1.19.2 | 5 / 17 | |
| 1.19.1 | 5 / 17 | |
| 1.19.0 | 5 / 17 | |
| 1.18.0 | 5 / 17 | |
| 1.17.0 | 5 / 17 | |
| 1.16.0 | 5 / 17 | |
| 1.15.0 | 5 / 17 | |
| 1.14.1 | 5 / 17 | |
| 1.14.0 | 5 / 17 | |
| 1.13.0 | 5 / 17 | |
| 1.12.1 | 5 / 17 | |
| 1.12.0 | 5 / 17 | |
| 1.11.1 | 5 / 17 | |
| 1.11.0 | 5 / 17 | |
| 1.10.0 | 5 / 17 | |
| 1.9.435 | 6 / 17 | |
| 1.9.434 | 6 / 17 | |
| 1.9.433 | 6 / 17 | |
| 1.9.432 | 6 / 17 | |
| 1.9.431 | 6 / 17 | |
| 1.9.430 | 6 / 17 | |
| 1.9.429 | 6 / 17 | |
| 1.9.428 | 6 / 17 | |
| 1.9.427 | 6 / 17 | |
| 1.9.426 | 6 / 17 | |
| 1.9.425 | 6 / 17 | |
| 1.9.424 | 6 / 17 | |
| 1.9.423 | 6 / 17 | |
| 1.9.422 | 6 / 17 | |
| 1.9.421 | 6 / 17 | |
| 1.9.420 | 6 / 17 | |
| 1.9.419 | 6 / 17 | |
| 1.9.418 | 6 / 17 | |
| 1.9.417 | 6 / 17 | |
| 1.9.416 | 6 / 17 | |
| 1.9.415 | 6 / 17 | |
| 1.9.414 | 6 / 17 | |
| 1.9.413 | 6 / 17 | |
| 1.9.412 | 6 / 17 | |
| 1.9.411 | 6 / 17 | |
| 1.9.410 | 6 / 17 | |
| 1.9.409 | 6 / 17 | |
| 1.9.408 | 6 / 17 | |
| 1.9.407 | 6 / 17 | |
| 1.9.406 | 6 / 17 |
v1.22.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.22.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.21.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.14.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.12.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.435
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.434
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.433
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.432
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.431
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.430
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.429
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.428
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.427
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.426
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.425
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.424
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.423
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.422
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.421
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.420
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.419
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.418
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.417
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.416
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.415
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.414
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.413
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.412
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.411
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.410
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.409
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.408
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.407
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.406
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.