@times-components/key-facts
Bulleted list of text data
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@times-components/utils | AI (dependencies): Same-org monorepo sibling; stable pattern across all @times-components versions. | ai | |
| dependencies | unvetted-dep:@times-components/responsive | AI (dependencies): Same-org monorepo sibling; stable pattern across all @times-components versions. | ai | |
| dependencies | unvetted-dep:@times-components/ts-components | AI (dependencies): Same-org monorepo sibling; stable pattern across all @times-components versions. | ai | |
| dependencies | unvetted-dep:@times-components/ts-styleguide | AI (dependencies): Same-org monorepo sibling; stable pattern across all @times-components versions. | ai | |
| provenance | no-provenance | AI (provenance): Long-established monorepo package; no provenance is consistent across all versions of this package family. | ai |
Versions (showing 47 of 47)
| Version | Deps | Published |
|---|---|---|
| 2.13.121 | 8 / 18 | |
| 2.13.120 | 8 / 18 | |
| 2.13.119 | 8 / 18 | |
| 2.13.118 | 8 / 18 | |
| 2.13.117 | 8 / 18 | |
| 2.13.115 | 8 / 18 | |
| 2.13.114 | 8 / 18 | |
| 2.13.113 | 8 / 18 | |
| 2.13.112 | 8 / 18 | |
| 2.13.111 | 8 / 18 | |
| 2.13.110 | 8 / 18 | |
| 2.13.108 | 8 / 18 | |
| 2.13.107 | 8 / 18 | |
| 2.13.105 | 8 / 18 | |
| 2.13.102 | 8 / 18 | |
| 2.13.101 | 8 / 18 | |
| 2.13.65 | 8 / 18 | |
| 2.13.53 | 8 / 18 | |
| 2.13.52 | 8 / 18 | |
| 2.13.51 | 8 / 18 | |
| 2.13.50 | 8 / 18 | |
| 2.13.49 | 8 / 18 | |
| 2.13.48 | 8 / 18 | |
| 2.13.47 | 8 / 18 | |
| 2.13.46 | 8 / 18 | |
| 2.13.45 | 8 / 18 | |
| 2.13.44 | 8 / 18 | |
| 2.13.43 | 8 / 18 | |
| 2.13.42 | 8 / 18 | |
| 2.13.41 | 8 / 18 | |
| 2.13.40 | 8 / 18 | |
| 2.13.39 | 8 / 18 | |
| 2.13.38 | 8 / 18 | |
| 2.13.37 | 8 / 18 | |
| 2.13.36 | 8 / 18 | |
| 2.13.35 | 8 / 18 | |
| 2.13.34 | 8 / 18 | |
| 2.13.33 | 8 / 18 | |
| 2.13.32 | 8 / 18 | |
| 2.13.31 | 8 / 18 | |
| 2.13.30 | 8 / 18 | |
| 2.13.29 | 8 / 18 | |
| 2.13.28 | 8 / 18 | |
| 2.13.27 | 8 / 18 | |
| 2.13.26 | 8 / 18 | |
| 2.13.25 | 8 / 18 | |
| 2.13.24 | 8 / 18 |
v2.13.121
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.120
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.119
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.118
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.117
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.115
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.114
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.113
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.112
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.111
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.110
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.108
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.13.107
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.105
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.13.102
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.13.101
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.13.65
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.13.53
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.13.52
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.38
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.13.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.13.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.