@times-components/author-profile
Author profile information along with a list of articles they have written
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@times-components/ts-styleguide | AI (dependencies): Sibling package from the same times-components monorepo; stable false positive. | ai | |
| dependencies | unvetted-dep:@times-components/link | AI (dependencies): Sibling package from the same times-components monorepo; stable false positive. | ai | |
| dependencies | unvetted-dep:@times-components/image | AI (dependencies): Sibling package from the same times-components monorepo; stable false positive. | ai | |
| dependencies | unvetted-dep:@times-components/utils | AI (dependencies): Sibling package from the same times-components monorepo; stable false positive. | ai | |
| dependencies | unvetted-dep:@times-components/gradient | AI (dependencies): Sibling package from the same times-components monorepo; stable false positive. | ai | |
| dependencies | unvetted-dep:@times-components/tracking | AI (dependencies): Sibling package from the same times-components monorepo; stable false positive. | ai | |
| dependencies | unvetted-dep:@times-components/pagination | AI (dependencies): Sibling package from the same times-components monorepo; stable false positive. | ai | |
| dependencies | unvetted-dep:@times-components/responsive | AI (dependencies): Sibling package from the same times-components monorepo; stable false positive. | ai | |
| dependencies | unvetted-dep:@times-components/ts-components | AI (dependencies): Sibling package from the same times-components monorepo; stable false positive. | ai | |
| provenance | no-provenance | AI (provenance): Established Times Components monorepo; provenance not used across the entire package family. | ai |
Versions (showing 51 of 74)
| Version | Deps | Published |
|---|---|---|
| 6.23.46 | 18 / 25 | |
| 6.23.45 | 18 / 25 | |
| 6.23.44 | 18 / 25 | |
| 6.23.43 | 18 / 25 | |
| 6.23.42 | 18 / 25 | |
| 6.23.40 | 18 / 25 | |
| 6.23.39 | 18 / 25 | |
| 6.23.38 | 18 / 25 | |
| 6.23.37 | 18 / 25 | |
| 6.23.36 | 18 / 25 | |
| 6.23.35 | 18 / 25 | |
| 6.23.34 | 18 / 25 | |
| 6.23.33 | 18 / 25 | |
| 6.23.32 | 18 / 25 | |
| 6.23.31 | 18 / 25 | |
| 6.23.30 | 18 / 25 | |
| 6.23.29 | 18 / 25 | |
| 6.23.28 | 18 / 25 | |
| 6.23.27 | 18 / 25 | |
| 6.23.26 | 18 / 25 | |
| 6.22.30 | 17 / 25 | |
| 6.22.29 | 17 / 25 | |
| 6.22.28 | 17 / 25 | |
| 6.22.27 | 17 / 25 | |
| 6.22.26 | 17 / 25 | |
| 6.22.25 | 17 / 25 | |
| 6.22.24 | 17 / 25 | |
| 6.22.23 | 17 / 25 | |
| 6.22.22 | 17 / 25 | |
| 6.22.21 | 17 / 25 | |
| 6.22.20 | 17 / 25 | |
| 6.22.19 | 17 / 25 | |
| 6.22.18 | 17 / 25 | |
| 6.22.17 | 17 / 25 | |
| 6.22.16 | 17 / 25 | |
| 6.22.15 | 17 / 25 | |
| 6.22.14 | 17 / 25 | |
| 6.22.13 | 17 / 25 | |
| 6.22.12 | 17 / 25 | |
| 6.22.11 | 17 / 25 | |
| 6.22.10 | 17 / 25 | |
| 6.22.9 | 17 / 25 | |
| 6.22.8 | 17 / 25 | |
| 6.22.7 | 17 / 25 | |
| 6.22.6 | 17 / 25 | |
| 6.22.5 | 17 / 25 | |
| 6.22.4 | 17 / 25 | |
| 6.22.3 | 17 / 25 | |
| 6.22.2 | 17 / 25 | |
| 6.22.1 | 17 / 25 | |
| 6.22.0 | 17 / 25 |
v6.23.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.23.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.23.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.23.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.22.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.22.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.22.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.22.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.22.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.22.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.22.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.