@times-components/ts-components
Reuseable Typescript React Components
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/components/opta/football/player-stats/__tests__/OptaFootballPlayerRanking.test.js | AI (source-diff): Readable transpiled test file in dist/; long lines are bundler output, not obfuscation. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/components/opta/football/starting-formations/__tests__/OptaFootballStartingFormations.test.js | AI (source-diff): Readable transpiled test file in dist/; long lines are bundler output, not obfuscation. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/components/opta/football/starting-formations/OptaFootballStartingFormations.js | AI (source-diff): Readable transpiled React component in dist/; long lines are bundler output, not obfuscation. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/components/opta/football/opta-match-stats/timeline/WidgetContainer.js | AI (source-diff): Readable styled-components source; long lines from template literals. | ai | |
| source-diff | obfuscated-file:dist/components/opta/football/opta-match-stats/momentum/tooltip.js | AI (source-diff): Readable styled-components React source; long lines from template literals. | ai | |
| source-diff | obfuscated-file:dist/components/opta/football/opta-match-stats/momentum/__tests__/tooltip.test.js | AI (source-diff): Readable test file; long lines from compiled test harness. | ai | |
| source-diff | obfuscated-file:dist/components/opta/football/opta-match-stats/__tests__/useAdaptiveMatchFeed.test.js | AI (source-diff): Readable test file; long lines from compiled test harness. | ai | |
| source-diff | obfuscated-file:dist/components/opta/football/opta-match-stats/momentum/useEventTooltip.js | AI (source-diff): Readable React hook source; long lines from template literals. | ai | |
| source-diff | obfuscated-file:dist/components/opta/football/opta-match-stats/momentum/__tests__/useEventTooltip.test.js | AI (source-diff): Readable test file; long lines from compiled test harness. | ai | |
| source-diff | obfuscated-file:dist/components/opta/football/opta-match-stats/timeline/OptaMatchStatsTimeline.js | AI (source-diff): Readable TypeScript/React dist output; long lines from template literals, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components/opta/football/opta-match-stats/timeline/__tests__/OptaMatchStatsTimeline.test.js | AI (source-diff): Readable test file; long lines from compiled test harness, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@times-components/related-articles | AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:@times-components/button | AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:regenerator-runtime | AI (phantom-deps): Known implicit runtime dep for transpiled async code; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-apollo | AI (phantom-deps): Used via provider/query deps; config-only reference is expected for this monorepo package. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Listed as both dep and devDep in a React component library; config-only reference is expected. | ai |
Versions (showing 22 of 222)
| Version | Deps | Published |
|---|---|---|
| 1.45.0 | 25 / 28 | |
| 1.44.2 | 25 / 28 | |
| 1.44.1 | 25 / 28 | |
| 1.44.0 | 25 / 28 | |
| 1.43.2 | 25 / 28 | |
| 1.43.1 | 25 / 28 | |
| 1.43.0 | 25 / 28 | |
| 1.42.0 | 25 / 28 | |
| 1.41.1 | 25 / 28 | |
| 1.41.0 | 25 / 28 | |
| 1.40.0 | 25 / 28 | |
| 1.39.0 | 25 / 28 | |
| 1.38.0 | 25 / 28 | |
| 1.37.0 | 25 / 28 | |
| 1.36.3 | 25 / 28 | |
| 1.36.2 | 25 / 28 | |
| 1.36.1 | 25 / 28 | |
| 1.36.0 | 25 / 28 | |
| 1.35.5 | 25 / 28 | |
| 1.35.4 | 25 / 28 | |
| 1.35.3 | 25 / 28 | |
| 1.35.2 | 25 / 28 |
v1.45.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.44.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.44.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.44.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.41.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.41.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.