@times-components/gradient
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Long-established monorepo package; provenance absence is consistent across all versions and poses no elevated risk here. | ai |
Versions (showing 51 of 153)
| Version | Deps | Published |
|---|---|---|
| 3.5.123 | 3 / 17 | |
| 3.5.122 | 3 / 17 | |
| 3.5.121 | 3 / 17 | |
| 3.5.120 | 3 / 17 | |
| 3.5.119 | 3 / 17 | |
| 3.5.118 | 3 / 17 | |
| 3.5.117 | 3 / 17 | |
| 3.5.116 | 3 / 17 | |
| 3.5.115 | 3 / 17 | |
| 3.5.114 | 3 / 17 | |
| 3.5.113 | 3 / 17 | |
| 3.5.112 | 3 / 17 | |
| 3.5.111 | 3 / 17 | |
| 3.5.110 | 3 / 17 | |
| 3.5.109 | 3 / 17 | |
| 3.5.108 | 3 / 17 | |
| 3.5.107 | 3 / 17 | |
| 3.5.106 | 3 / 17 | |
| 3.5.105 | 3 / 17 | |
| 3.5.104 | 3 / 17 | |
| 3.5.103 | 3 / 17 | |
| 3.5.102 | 3 / 17 | |
| 3.5.101 | 3 / 17 | |
| 3.5.100 | 3 / 17 | |
| 3.5.99 | 3 / 17 | |
| 3.5.98 | 3 / 17 | |
| 3.5.97 | 3 / 17 | |
| 3.5.96 | 3 / 17 | |
| 3.5.95 | 3 / 17 | |
| 3.5.94 | 3 / 17 | |
| 3.5.93 | 3 / 17 | |
| 3.5.92 | 3 / 17 | |
| 3.5.91 | 3 / 17 | |
| 3.5.90 | 3 / 17 | |
| 3.5.89 | 3 / 17 | |
| 3.5.88 | 3 / 17 | |
| 3.5.87 | 3 / 17 | |
| 3.5.86 | 3 / 17 | |
| 3.5.85 | 3 / 17 | |
| 3.5.84 | 3 / 17 | |
| 3.5.83 | 3 / 17 | |
| 3.5.82 | 3 / 17 | |
| 3.5.81 | 3 / 17 | |
| 3.5.80 | 3 / 17 | |
| 3.5.79 | 3 / 17 | |
| 3.5.78 | 3 / 17 | |
| 3.5.77 | 3 / 17 | |
| 3.5.76 | 3 / 17 | |
| 3.5.75 | 3 / 17 | |
| 3.5.74 | 3 / 17 | |
| 3.5.73 | 3 / 17 |
v3.5.77
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.76
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.75
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.74
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.73
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.