@workday/canvas-kit-docs
Documentation components of Canvas Kit components
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@workday/canvas-kit-labs-react | AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic is a stable false positive for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@workday/canvas-expressive-icons-web | AI (phantom-deps): Same-org asset dep; phantom-dep heuristic is a stable false positive for this monorepo package. | ai | |
| phantom-deps | phantom-dep:ts-node | AI (phantom-deps): Used in build scripts; phantom-dep false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Used transitively via canvas-kit-react; phantom-dep false positive for this package. | ai |
Versions (showing 17 of 117)
| Version | Deps | Published |
|---|---|---|
| 13.2.57 | 12 / 4 | |
| 13.2.56 | 12 / 4 | |
| 13.2.55 | 12 / 4 | |
| 13.2.54 | 12 / 4 | |
| 13.2.53 | 12 / 4 | |
| 13.2.52 | 12 / 4 | |
| 13.2.51 | 12 / 4 | |
| 13.2.50 | 12 / 4 | |
| 13.2.49 | 12 / 4 | |
| 13.2.48 | 12 / 4 | |
| 13.2.47 | 12 / 4 | |
| 13.2.46 | 12 / 4 | |
| 13.2.45 | 12 / 4 | |
| 13.2.44 | 12 / 4 | |
| 13.2.43 | 12 / 4 | |
| 13.2.42 | 12 / 4 | |
| 13.2.41 | 12 / 4 |
v13.2.56
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.55
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.54
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.53
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.51
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.50
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.49
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.48
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.47
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.45
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.2.44
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.2.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.2.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.2.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.