@times-components/provider
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Established Times Components monorepo package; lack of Sigstore provenance is consistent across all versions and not a risk indicator here. | ai | |
| phantom-deps | phantom-dep:graphql-tag | AI (phantom-deps): graphql-tag is a declared runtime dep; phantom-dep heuristic misfires for this package. | ai | |
| phantom-deps | phantom-dep:@times-components/utils | AI (phantom-deps): Same-org dep used transitively; stable false positive for this monorepo package. | ai |
Versions (showing 100 of 464)
| Version | Deps | Published |
|---|---|---|
| 1.48.40 | 9 / 22 | |
| 1.48.39 | 9 / 22 | |
| 1.48.38 | 9 / 22 | |
| 1.48.37 | 9 / 22 | |
| 1.48.36 | 9 / 22 | |
| 1.48.35 | 9 / 22 | |
| 1.48.34 | 9 / 22 | |
| 1.48.33 | 9 / 22 | |
| 1.48.32 | 9 / 22 | |
| 1.48.31 | 9 / 22 | |
| 1.48.30 | 9 / 22 | |
| 1.48.29 | 9 / 22 | |
| 1.48.28 | 9 / 22 | |
| 1.48.27 | 9 / 22 | |
| 1.48.26 | 9 / 22 | |
| 1.48.25 | 9 / 22 | |
| 1.48.24 | 9 / 22 | |
| 1.48.23 | 9 / 22 | |
| 1.48.22 | 9 / 22 | |
| 1.48.21 | 9 / 22 | |
| 1.48.20 | 9 / 22 | |
| 1.48.19 | 9 / 22 | |
| 1.48.18 | 9 / 22 | |
| 1.48.17 | 9 / 22 | |
| 1.48.16 | 9 / 22 | |
| 1.48.15 | 9 / 22 | |
| 1.48.14 | 9 / 22 | |
| 1.48.13 | 9 / 22 | |
| 1.48.12 | 9 / 22 | |
| 1.48.11 | 9 / 22 | |
| 1.48.10 | 9 / 22 | |
| 1.48.9 | 9 / 22 | |
| 1.48.8 | 9 / 22 | |
| 1.48.7 | 9 / 22 | |
| 1.48.6 | 9 / 22 | |
| 1.48.5 | 9 / 22 | |
| 1.48.4 | 9 / 22 | |
| 1.48.3 | 9 / 22 | |
| 1.48.2 | 9 / 22 | |
| 1.48.1 | 9 / 22 | |
| 1.48.0 | 9 / 22 | |
| 1.47.0 | 9 / 22 | |
| 1.46.0 | 9 / 22 | |
| 1.45.1 | 9 / 22 | |
| 1.45.0 | 9 / 22 | |
| 1.44.1 | 9 / 22 | |
| 1.44.0 | 9 / 22 | |
| 1.43.0 | 9 / 22 | |
| 1.42.2 | 9 / 22 | |
| 1.42.1 | 9 / 22 | |
| 1.42.0 | 9 / 22 | |
| 1.41.16 | 9 / 22 | |
| 1.41.15 | 9 / 22 | |
| 1.41.14 | 9 / 22 | |
| 1.41.13 | 9 / 22 | |
| 1.41.12 | 9 / 22 | |
| 1.41.11 | 9 / 22 | |
| 1.41.10 | 9 / 22 | |
| 1.41.9 | 9 / 22 | |
| 1.41.8 | 9 / 22 | |
| 1.41.7 | 9 / 22 | |
| 1.41.6 | 9 / 22 | |
| 1.41.5 | 9 / 22 | |
| 1.41.4 | 9 / 22 | |
| 1.41.3 | 9 / 22 | |
| 1.41.2 | 9 / 22 | |
| 1.41.1 | 9 / 22 | |
| 1.41.0 | 9 / 22 | |
| 1.40.35 | 9 / 22 | |
| 1.40.34 | 9 / 22 | |
| 1.40.33 | 9 / 22 | |
| 1.40.32 | 9 / 22 | |
| 1.40.31 | 9 / 22 | |
| 1.40.30 | 9 / 22 | |
| 1.40.29 | 9 / 22 | |
| 1.40.28 | 9 / 22 | |
| 1.40.27 | 9 / 22 | |
| 1.40.26 | 9 / 22 | |
| 1.40.25 | 9 / 22 | |
| 1.40.24 | 9 / 22 | |
| 1.40.23 | 9 / 22 | |
| 1.40.22 | 9 / 22 | |
| 1.40.21 | 9 / 22 | |
| 1.40.20 | 9 / 22 | |
| 1.40.19 | 9 / 22 | |
| 1.40.18 | 9 / 22 | |
| 1.40.17 | 9 / 22 | |
| 1.40.16 | 9 / 22 | |
| 1.40.15 | 9 / 22 | |
| 1.40.14 | 9 / 22 | |
| 1.40.13 | 9 / 22 | |
| 1.40.12 | 9 / 22 | |
| 1.40.11 | 9 / 22 | |
| 1.40.10 | 9 / 22 | |
| 1.40.9 | 9 / 22 | |
| 1.40.8 | 9 / 22 | |
| 1.40.7 | 9 / 22 | |
| 1.40.6 | 9 / 22 | |
| 1.40.5 | 9 / 22 | |
| 1.40.4 | 9 / 22 |
v1.43.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.42.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.40.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.