@times-components/gradient
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Long-established monorepo package; provenance absence is consistent across all versions and poses no elevated risk here. | ai |
Versions (showing 100 of 153)
| Version | Deps | Published |
|---|---|---|
| 3.5.123 | 3 / 17 | |
| 3.5.122 | 3 / 17 | |
| 3.5.121 | 3 / 17 | |
| 3.5.120 | 3 / 17 | |
| 3.5.119 | 3 / 17 | |
| 3.5.118 | 3 / 17 | |
| 3.5.117 | 3 / 17 | |
| 3.5.116 | 3 / 17 | |
| 3.5.115 | 3 / 17 | |
| 3.5.114 | 3 / 17 | |
| 3.5.113 | 3 / 17 | |
| 3.5.112 | 3 / 17 | |
| 3.5.111 | 3 / 17 | |
| 3.5.110 | 3 / 17 | |
| 3.5.109 | 3 / 17 | |
| 3.5.108 | 3 / 17 | |
| 3.5.107 | 3 / 17 | |
| 3.5.106 | 3 / 17 | |
| 3.5.105 | 3 / 17 | |
| 3.5.104 | 3 / 17 | |
| 3.5.103 | 3 / 17 | |
| 3.5.102 | 3 / 17 | |
| 3.5.101 | 3 / 17 | |
| 3.5.100 | 3 / 17 | |
| 3.5.99 | 3 / 17 | |
| 3.5.98 | 3 / 17 | |
| 3.5.97 | 3 / 17 | |
| 3.5.96 | 3 / 17 | |
| 3.5.95 | 3 / 17 | |
| 3.5.94 | 3 / 17 | |
| 3.5.93 | 3 / 17 | |
| 3.5.92 | 3 / 17 | |
| 3.5.91 | 3 / 17 | |
| 3.5.90 | 3 / 17 | |
| 3.5.89 | 3 / 17 | |
| 3.5.88 | 3 / 17 | |
| 3.5.87 | 3 / 17 | |
| 3.5.86 | 3 / 17 | |
| 3.5.85 | 3 / 17 | |
| 3.5.84 | 3 / 17 | |
| 3.5.83 | 3 / 17 | |
| 3.5.82 | 3 / 17 | |
| 3.5.81 | 3 / 17 | |
| 3.5.80 | 3 / 17 | |
| 3.5.79 | 3 / 17 | |
| 3.5.78 | 3 / 17 | |
| 3.5.77 | 3 / 17 | |
| 3.5.76 | 3 / 17 | |
| 3.5.75 | 3 / 17 | |
| 3.5.74 | 3 / 17 | |
| 3.5.73 | 3 / 17 | |
| 3.5.72 | 3 / 17 | |
| 3.5.71 | 3 / 17 | |
| 3.5.70 | 3 / 17 | |
| 3.5.69 | 3 / 17 | |
| 3.5.68 | 3 / 17 | |
| 3.5.67 | 3 / 17 | |
| 3.5.66 | 3 / 17 | |
| 3.5.65 | 3 / 17 | |
| 3.5.64 | 3 / 17 | |
| 3.5.63 | 3 / 17 | |
| 3.5.62 | 3 / 17 | |
| 3.5.61 | 3 / 17 | |
| 3.5.60 | 3 / 17 | |
| 3.5.59 | 3 / 17 | |
| 3.5.58 | 3 / 17 | |
| 3.5.57 | 3 / 17 | |
| 3.5.56 | 3 / 17 | |
| 3.5.55 | 3 / 17 | |
| 3.5.54 | 3 / 17 | |
| 3.5.53 | 3 / 17 | |
| 3.5.52 | 3 / 17 | |
| 3.5.51 | 3 / 17 | |
| 3.5.50 | 3 / 17 | |
| 3.5.49 | 3 / 17 | |
| 3.5.48 | 3 / 17 | |
| 3.5.47 | 3 / 17 | |
| 3.5.46 | 3 / 17 | |
| 3.5.45 | 3 / 17 | |
| 3.5.44 | 3 / 17 | |
| 3.5.43 | 3 / 17 | |
| 3.5.42 | 3 / 17 | |
| 3.5.41 | 3 / 17 | |
| 3.5.40 | 3 / 17 | |
| 3.5.39 | 3 / 17 | |
| 3.5.38 | 3 / 17 | |
| 3.5.37 | 3 / 17 | |
| 3.5.36 | 3 / 17 | |
| 3.5.35 | 3 / 17 | |
| 3.5.34 | 3 / 17 | |
| 3.5.33 | 3 / 17 | |
| 3.5.32 | 3 / 17 | |
| 3.5.31 | 3 / 17 | |
| 3.5.30 | 3 / 17 | |
| 3.5.29 | 3 / 17 | |
| 3.5.28 | 3 / 17 | |
| 3.5.27 | 3 / 17 | |
| 3.5.26 | 3 / 17 | |
| 3.5.25 | 3 / 17 | |
| 3.5.24 | 3 / 17 |
v3.5.77
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.76
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.75
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.74
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.73
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.72
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.71
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.70
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.69
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.68
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.67
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.66
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.65
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.64
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.63
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.62
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.61
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.60
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.59
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.58
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.57
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.56
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.55
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.54
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.53
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.52
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.