@times-components/button
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Large established monorepo; lack of Sigstore provenance is consistent across all versions and not a risk signal here. | ai |
Versions (showing 100 of 160)
| Version | Deps | Published |
|---|---|---|
| 2.10.123 | 3 / 17 | |
| 2.10.122 | 3 / 17 | |
| 2.10.121 | 3 / 17 | |
| 2.10.120 | 3 / 17 | |
| 2.10.119 | 3 / 17 | |
| 2.10.118 | 3 / 17 | |
| 2.10.117 | 3 / 17 | |
| 2.10.116 | 3 / 17 | |
| 2.10.115 | 3 / 17 | |
| 2.10.114 | 3 / 17 | |
| 2.10.113 | 3 / 17 | |
| 2.10.112 | 3 / 17 | |
| 2.10.111 | 3 / 17 | |
| 2.10.110 | 3 / 17 | |
| 2.10.109 | 3 / 17 | |
| 2.10.108 | 3 / 17 | |
| 2.10.107 | 3 / 17 | |
| 2.10.106 | 3 / 17 | |
| 2.10.105 | 3 / 17 | |
| 2.10.104 | 3 / 17 | |
| 2.10.103 | 3 / 17 | |
| 2.10.102 | 3 / 17 | |
| 2.10.101 | 3 / 17 | |
| 2.10.100 | 3 / 17 | |
| 2.10.99 | 3 / 17 | |
| 2.10.98 | 3 / 17 | |
| 2.10.97 | 3 / 17 | |
| 2.10.96 | 3 / 17 | |
| 2.10.95 | 3 / 17 | |
| 2.10.94 | 3 / 17 | |
| 2.10.93 | 3 / 17 | |
| 2.10.92 | 3 / 17 | |
| 2.10.91 | 3 / 17 | |
| 2.10.90 | 3 / 17 | |
| 2.10.89 | 3 / 17 | |
| 2.10.88 | 3 / 17 | |
| 2.10.87 | 3 / 17 | |
| 2.10.86 | 3 / 17 | |
| 2.10.85 | 3 / 17 | |
| 2.10.84 | 3 / 17 | |
| 2.10.83 | 3 / 17 | |
| 2.10.82 | 3 / 17 | |
| 2.10.81 | 3 / 17 | |
| 2.10.80 | 3 / 17 | |
| 2.10.79 | 3 / 17 | |
| 2.10.78 | 3 / 17 | |
| 2.10.77 | 3 / 17 | |
| 2.10.76 | 3 / 17 | |
| 2.10.75 | 3 / 17 | |
| 2.10.74 | 3 / 17 | |
| 2.10.73 | 3 / 17 | |
| 2.10.72 | 3 / 17 | |
| 2.10.71 | 3 / 17 | |
| 2.10.70 | 3 / 17 | |
| 2.10.69 | 3 / 17 | |
| 2.10.68 | 3 / 17 | |
| 2.10.67 | 3 / 17 | |
| 2.10.66 | 3 / 17 | |
| 2.10.65 | 3 / 17 | |
| 2.10.64 | 3 / 17 | |
| 2.10.63 | 3 / 17 | |
| 2.10.62 | 3 / 17 | |
| 2.10.61 | 3 / 17 | |
| 2.10.60 | 3 / 17 | |
| 2.10.59 | 3 / 17 | |
| 2.10.58 | 3 / 17 | |
| 2.10.57 | 3 / 17 | |
| 2.10.56 | 3 / 17 | |
| 2.10.55 | 3 / 17 | |
| 2.10.54 | 3 / 17 | |
| 2.10.53 | 3 / 17 | |
| 2.10.52 | 3 / 17 | |
| 2.10.51 | 3 / 17 | |
| 2.10.50 | 3 / 17 | |
| 2.10.49 | 3 / 17 | |
| 2.10.48 | 3 / 17 | |
| 2.10.47 | 3 / 17 | |
| 2.10.46 | 3 / 17 | |
| 2.10.45 | 3 / 17 | |
| 2.10.44 | 3 / 17 | |
| 2.10.43 | 3 / 17 | |
| 2.10.42 | 3 / 17 | |
| 2.10.41 | 3 / 17 | |
| 2.10.40 | 3 / 17 | |
| 2.10.39 | 3 / 17 | |
| 2.10.38 | 3 / 17 | |
| 2.10.37 | 3 / 17 | |
| 2.10.36 | 3 / 17 | |
| 2.10.35 | 3 / 17 | |
| 2.10.34 | 3 / 17 | |
| 2.10.33 | 3 / 17 | |
| 2.10.32 | 3 / 17 | |
| 2.10.31 | 3 / 17 | |
| 2.10.30 | 3 / 17 | |
| 2.10.29 | 3 / 17 | |
| 2.10.28 | 3 / 17 | |
| 2.10.27 | 3 / 17 | |
| 2.10.26 | 3 / 17 | |
| 2.10.25 | 3 / 17 | |
| 2.10.24 | 3 / 17 |
v2.10.77
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.76
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.75
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.74
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.73
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.72
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.71
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.70
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.69
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.68
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.67
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.66
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.65
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.64
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.63
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.62
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.61
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.60
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.59
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.58
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.57
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.56
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.55
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.54
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.53
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.52
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.