@trackunit/ui-icons
The `@trackunit/ui-icons` package is used by the Icon component in [@trackunit/react-components](https://www.npmjs.com/package/@trackunit/react-components).
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Long-standing package; provenance absence is a best-practice gap, not a security blocker. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established icon library; README link dump and missing keywords are metadata quirks, not spam indicators. | ai | |
| dependencies | unvetted-dep:svgo | AI (dependencies): svgo is a standard SVG optimizer; expected dependency for an icon library package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established Trackunit org package with 723 versions and 8 approved dependents; dormancy likely reflects org publishing cadence, not takeover. | ai | |
| phantom-deps | phantom-dep:glob | AI (phantom-deps): Build tooling dep; not a runtime import, stable pattern for this icon package. | ai | |
| phantom-deps | phantom-dep:string-ts | AI (phantom-deps): Build tooling dep; not a runtime import, stable pattern for this icon package. | ai | |
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): Build tooling dep; not a runtime import, stable pattern for this icon package. | ai | |
| phantom-deps | phantom-dep:jsdom | AI (phantom-deps): Build tooling dep; not a runtime import, stable pattern for this icon package. | ai |
Versions (showing 100 of 560)
| Version | Deps | Published |
|---|---|---|
| 1.9.16 | 5 / 0 | |
| 1.9.15 | 5 / 0 | |
| 1.9.14 | 5 / 0 | |
| 1.9.12 | 5 / 0 | |
| 1.9.10 | 5 / 0 | |
| 1.9.9 | 5 / 0 | |
| 1.9.7 | 5 / 0 | |
| 1.9.6 | 5 / 0 | |
| 1.9.5 | 5 / 0 | |
| 1.9.4 | 5 / 0 | |
| 1.9.3 | 5 / 0 | |
| 1.9.2 | 5 / 0 | |
| 1.9.1 | 5 / 0 | |
| 1.9.0 | 5 / 0 | |
| 1.8.0 | 5 / 0 | |
| 1.7.123 | 5 / 0 | |
| 1.7.122 | 5 / 0 | |
| 1.7.120 | 5 / 0 | |
| 1.7.119 | 5 / 0 | |
| 1.7.116 | 5 / 0 | |
| 1.7.114 | 5 / 0 | |
| 1.7.111 | 5 / 0 | |
| 1.7.108 | 5 / 0 | |
| 1.7.107 | 5 / 0 | |
| 1.7.105 | 5 / 0 | |
| 1.7.104 | 5 / 0 | |
| 1.7.100 | 5 / 0 | |
| 1.7.98 | 5 / 0 | |
| 1.7.97 | 5 / 0 | |
| 1.7.95 | 5 / 0 | |
| 1.7.94 | 5 / 0 | |
| 1.7.93 | 5 / 0 | |
| 1.7.90 | 5 / 0 | |
| 1.7.89 | 5 / 0 | |
| 1.7.87 | 5 / 0 | |
| 1.7.85 | 5 / 0 | |
| 1.7.83 | 5 / 0 | |
| 1.7.82 | 5 / 0 | |
| 1.7.81 | 5 / 0 | |
| 1.7.80 | 5 / 0 | |
| 1.7.79 | 5 / 0 | |
| 1.7.78 | 5 / 0 | |
| 1.7.76 | 5 / 0 | |
| 1.7.75 | 5 / 0 | |
| 1.7.74 | 5 / 0 | |
| 1.7.73 | 5 / 0 | |
| 1.7.71 | 5 / 0 | |
| 1.7.70 | 5 / 0 | |
| 1.7.65 | 5 / 0 | |
| 1.7.64 | 5 / 0 | |
| 1.7.63 | 5 / 0 | |
| 1.7.62 | 5 / 0 | |
| 1.7.61 | 5 / 0 | |
| 1.7.60 | 5 / 0 | |
| 1.7.59 | 5 / 0 | |
| 1.7.58 | 5 / 0 | |
| 1.7.57 | 5 / 0 | |
| 1.7.54 | 5 / 0 | |
| 1.7.53 | 5 / 0 | |
| 1.7.52 | 5 / 0 | |
| 1.7.51 | 5 / 0 | |
| 1.7.50 | 5 / 0 | |
| 1.7.49 | 5 / 0 | |
| 1.7.48 | 5 / 0 | |
| 1.7.47 | 5 / 0 | |
| 1.7.45 | 5 / 0 | |
| 1.7.44 | 5 / 0 | |
| 1.7.43 | 5 / 0 | |
| 1.7.42 | 5 / 0 | |
| 1.7.41 | 5 / 0 | |
| 1.7.40 | 5 / 0 | |
| 1.7.39 | 5 / 0 | |
| 1.7.38 | 5 / 0 | |
| 1.7.37 | 5 / 0 | |
| 1.7.36 | 5 / 0 | |
| 1.7.34 | 5 / 0 | |
| 1.7.33 | 5 / 0 | |
| 1.7.32 | 5 / 0 | |
| 1.7.31 | 5 / 0 | |
| 1.7.29 | 5 / 0 | |
| 1.7.28 | 5 / 0 | |
| 1.7.26 | 5 / 0 | |
| 1.7.25 | 5 / 0 | |
| 1.7.24 | 5 / 0 | |
| 1.7.23 | 5 / 0 | |
| 1.7.21 | 5 / 0 | |
| 1.7.20 | 5 / 0 | |
| 1.7.19 | 5 / 0 | |
| 1.7.18 | 5 / 0 | |
| 1.7.16 | 5 / 0 | |
| 1.7.15 | 5 / 0 | |
| 1.7.14 | 5 / 0 | |
| 1.7.13 | 5 / 0 | |
| 1.7.12 | 5 / 0 | |
| 1.7.10 | 5 / 0 | |
| 1.7.9 | 5 / 0 | |
| 1.7.8 | 5 / 0 | |
| 1.7.7 | 5 / 0 | |
| 1.7.6 | 5 / 0 | |
| 1.7.5 | 5 / 0 |
v1.9.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.123
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.122
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.120
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.119
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.116
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.114
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.111
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.108
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.107
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.105
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.104
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.100
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.98
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.97
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.95
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.94
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.93
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.90
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.89
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.87
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.85
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.83
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.82
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.81
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.80
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.79
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.78
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.76
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.75
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.74
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.73
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.71
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.70
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.65
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.64
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.63
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.62
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.61
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.60
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.59
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.58
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.57
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.54
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.53
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.52
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.40
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.37
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.