← Home

@workday/canvas-kit-react

The parent module that contains all Workday Canvas Kit React components

17
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

workday-canvas-kitmannycarrera4raisa.primerovaalanbsmithjaclynjessupjheddingssheelah

Keywords

canvascanvas-kitreactcomponentsworkday

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/commonjs/pill/lib/Pill.js AI (source-diff): Long lines are inlined CSS-in-JS style strings from canvas-kit-styling; not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/es6/pill/lib/Pill.js AI (source-diff): Same CSS-in-JS build artifact pattern; not obfuscation. Stable for this package. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Used in a documented object proxy/theming utility; standard JS Proxy pattern, not obfuscation. ai
phantom-deps phantom-dep:@workday/canvas-kit-preview-react AI (phantom-deps): Same org scope (@workday); declared as dep, likely used in dist bundle rather than direct import. ai

Versions (showing 17 of 117)

Version Deps Published
13.2.57 17 / 2
13.2.56 17 / 2
13.2.55 17 / 2
13.2.54 17 / 2
13.2.53 17 / 2
13.2.52 17 / 2
13.2.51 17 / 2
13.2.50 17 / 2
13.2.49 17 / 2
13.2.48 17 / 2
13.2.47 17 / 2
13.2.46 17 / 2
13.2.45 17 / 2
13.2.44 17 / 2
13.2.43 17 / 2
13.2.42 17 / 2
13.2.41 17 / 2

v13.2.56

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.55

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.54

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.53

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.52

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.51

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.50

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.49

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.48

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.47

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.2.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v13.2.44

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v13.2.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v13.2.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v13.2.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.