@times-components/button
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Large established monorepo; lack of Sigstore provenance is consistent across all versions and not a risk signal here. | ai |
Versions (showing 51 of 160)
| Version | Deps | Published |
|---|---|---|
| 2.10.123 | 3 / 17 | |
| 2.10.122 | 3 / 17 | |
| 2.10.121 | 3 / 17 | |
| 2.10.120 | 3 / 17 | |
| 2.10.119 | 3 / 17 | |
| 2.10.118 | 3 / 17 | |
| 2.10.117 | 3 / 17 | |
| 2.10.116 | 3 / 17 | |
| 2.10.115 | 3 / 17 | |
| 2.10.114 | 3 / 17 | |
| 2.10.113 | 3 / 17 | |
| 2.10.112 | 3 / 17 | |
| 2.10.111 | 3 / 17 | |
| 2.10.110 | 3 / 17 | |
| 2.10.109 | 3 / 17 | |
| 2.10.108 | 3 / 17 | |
| 2.10.107 | 3 / 17 | |
| 2.10.106 | 3 / 17 | |
| 2.10.105 | 3 / 17 | |
| 2.10.104 | 3 / 17 | |
| 2.10.103 | 3 / 17 | |
| 2.10.102 | 3 / 17 | |
| 2.10.101 | 3 / 17 | |
| 2.10.100 | 3 / 17 | |
| 2.10.99 | 3 / 17 | |
| 2.10.98 | 3 / 17 | |
| 2.10.97 | 3 / 17 | |
| 2.10.96 | 3 / 17 | |
| 2.10.95 | 3 / 17 | |
| 2.10.94 | 3 / 17 | |
| 2.10.93 | 3 / 17 | |
| 2.10.92 | 3 / 17 | |
| 2.10.91 | 3 / 17 | |
| 2.10.90 | 3 / 17 | |
| 2.10.89 | 3 / 17 | |
| 2.10.88 | 3 / 17 | |
| 2.10.87 | 3 / 17 | |
| 2.10.86 | 3 / 17 | |
| 2.10.85 | 3 / 17 | |
| 2.10.84 | 3 / 17 | |
| 2.10.83 | 3 / 17 | |
| 2.10.82 | 3 / 17 | |
| 2.10.81 | 3 / 17 | |
| 2.10.80 | 3 / 17 | |
| 2.10.79 | 3 / 17 | |
| 2.10.78 | 3 / 17 | |
| 2.10.77 | 3 / 17 | |
| 2.10.76 | 3 / 17 | |
| 2.10.75 | 3 / 17 | |
| 2.10.74 | 3 / 17 | |
| 2.10.73 | 3 / 17 |
v2.10.77
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.76
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.75
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.74
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.73
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.