← Home

@workday/canvas-kit-labs-react

Canvas Kit Labs is an incubator for new and experimental components. Since we have a rather rigorous process for getting components in at a production level, it can be valuable to make them available earlier while we continuously iterate on the API/functi

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

Verified SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

workday-canvas-kitmannycarrera4raisa.primerovaalanbsmithjaclynjessupjheddingssheelah

Keywords

canvascanvas-kitreactcomponentsworkday

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Transition to automated CI publishing; human maintainer removal is expected alongside GitHub Actions publisher. ai
provenance publisher-changed AI (provenance): Workday org migrated publishing to GitHub Actions CI/CD with SLSA attestation; stable pattern for this package going forward. ai
phantom-deps phantom-dep:@workday/design-assets-types AI (phantom-deps): Same-org dependency; phantom-dep heuristic false positive for this monorepo package. ai
phantom-deps phantom-dep:@workday/canvas-kit-styling AI (phantom-deps): Same-org dependency; phantom-dep heuristic false positive for this monorepo package. ai
phantom-deps phantom-dep:@workday/canvas-tokens-web AI (phantom-deps): Same-org dependency; phantom-dep heuristic false positive for this monorepo package. ai
provenance no-provenance AI (provenance): Established Workday org package; lack of provenance is consistent across all versions and not a risk indicator here. ai
phantom-deps phantom-dep:chroma-js AI (phantom-deps): Peer/config dependency pattern for UI component library; stable false positive. ai
phantom-deps phantom-dep:@workday/canvas-system-icons-web AI (phantom-deps): Same-org sibling package; config-level reference is expected. ai
phantom-deps phantom-dep:@emotion/styled AI (phantom-deps): Peer dependency for CSS-in-JS styling; expected for Canvas Kit component library. ai
phantom-deps phantom-dep:lodash.flatten AI (phantom-deps): Config-level reference; stable false positive for this package. ai
phantom-deps phantom-dep:@emotion/react AI (phantom-deps): Peer dependency for CSS-in-JS styling; expected for Canvas Kit component library. ai

Versions (showing 51 of 137)

View all versions
Version Deps Published
15.1.4 10 / 1
15.1.3 10 / 1
15.1.1 10 / 1
15.1.0 10 / 1
15.0.21 10 / 1
15.0.20 10 / 1
15.0.19 10 / 1
15.0.18 10 / 1
15.0.17 10 / 1
15.0.16 10 / 1
15.0.15 10 / 1
15.0.14 10 / 1
15.0.13 10 / 1
15.0.12 10 / 1
15.0.11 10 / 1
15.0.9 10 / 1
15.0.8 10 / 1
15.0.7 10 / 1
15.0.6 10 / 1
15.0.5 10 / 1
15.0.4 10 / 1
15.0.3 10 / 1
15.0.2 10 / 1
15.0.1 10 / 1
15.0.0 10 / 1
14.3.17 10 / 1
14.3.16 10 / 1
14.3.15 10 / 1
14.3.14 10 / 1
14.3.13 10 / 1
14.3.12 10 / 1
14.3.11 10 / 1
14.3.10 10 / 1
14.3.9 10 / 1
14.3.8 10 / 1
14.3.7 10 / 1
14.3.6 10 / 1
14.3.5 10 / 1
14.3.4 10 / 1
14.3.3 10 / 1
14.3.2 10 / 1
14.3.1 10 / 1
14.3.0 10 / 1
14.2.37 10 / 1
14.2.36 10 / 1
14.2.35 10 / 1
14.2.34 10 / 1
14.2.33 10 / 1
14.2.32 10 / 1
14.2.31 10 / 1
14.2.30 10 / 1

v15.1.4

1 finding
INFO Has verified SLSA provenance attestation provenance

Published via CI/CD with a Sigstore attestation that VERIFIED against the pinned Sigstore trust root (predicate: https://slsa.dev/provenance/v1, issuer: https://token.actions.githubusercontent.com). The attestation's sha512 subject digest matches the tarball bytes we streamed, so it describes this exact artifact. This is the strongest supply chain integrity signal.

v15.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v15.0.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.3.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.