simple-icons
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| email-domain | unclaimed-email:adamrusted.me | AI (email-domain): Stale maintainer email; package has SLSA provenance via GitHub Actions, mitigating domain-takeover risk. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): simple-icons is a long-established package (391 versions, 3143 days old) with CI/CD publishing and SLSA attestation; dormancy gaps are not indicative of takeover for this package. | ai | |
| provenance | slsa-provenance | AI (provenance): simple-icons consistently publishes via CI/CD with SLSA provenance; this is expected and stable for this package. | ai |
Versions (showing 36 of 36)
| Version | Deps | Published |
|---|---|---|
| 16.27.1 | 0 / 25 | |
| 16.27.0 | 0 / 25 | |
| 16.26.0 | 0 / 25 | |
| 16.25.0 | 0 / 25 | |
| 16.24.1 | 0 / 25 | |
| 16.24.0 | 0 / 25 | |
| 16.23.0 | 0 / 25 | |
| 16.22.0 | 0 / 25 | |
| 16.21.0 | 0 / 25 | |
| 16.20.0 | 0 / 25 | |
| 16.19.0 | 0 / 25 | |
| 16.18.1 | 0 / 25 | |
| 16.18.0 | 0 / 25 | |
| 16.17.0 | 0 / 25 | |
| 16.16.0 | 0 / 25 | |
| 16.15.0 | 0 / 25 | |
| 16.14.0 | 0 / 25 | |
| 16.13.0 | 0 / 25 | |
| 16.12.0 | 0 / 25 | |
| 16.11.0 | 0 / 25 | |
| 16.10.0 | 0 / 25 | |
| 16.9.0 | 0 / 25 | |
| 16.8.0 | 0 / 25 | |
| 16.7.0 | 0 / 25 | |
| 16.6.1 | 0 / 25 | |
| 16.6.0 | 0 / 25 | |
| 16.5.0 | 0 / 25 | |
| 16.4.0 | 0 / 25 | |
| 16.3.0 | 0 / 25 | |
| 16.2.0 | 0 / 25 | |
| 16.1.0 | 0 / 25 | |
| 16.0.0 | 0 / 25 | |
| 15.22.0 | 0 / 25 | |
| 15.21.0 | 0 / 25 | |
| 15.20.0 | 0 / 25 | |
| 15.19.0 | 0 / 25 |
v16.27.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v16.27.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v16.26.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v16.25.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v16.24.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.