← Home

tailwindcss-patch

38
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

icebreaker

Keywords

tailwindcsspatchextractclass

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions with SLSA attestation; CI/CD publishing is legitimate for this established package. ai
semgrep semgrep:dynamic-require AI (semgrep): Context-registry loading user tailwind config modules at runtime; expected pattern for this patching tool. ai
dependencies unvetted-dep:tailwindcss-config AI (dependencies): Sibling/related package in the tailwindcss-mangle ecosystem; stable dependency across versions. ai
dependencies unvetted-dep:@tailwindcss-mangle/config AI (dependencies): First-party sibling package from the same monorepo (sonofmagic/tailwindcss-mangle). ai

Versions (showing 38 of 38)

Version Deps Published
10.0.1 14 / 5
10.0.0 14 / 5
9.5.1 14 / 5
9.5.0 14 / 5
9.4.4 16 / 5
9.4.3 16 / 5
9.4.2 16 / 5
9.4.1 16 / 5
9.4.0 16 / 5
9.3.7 16 / 5
9.3.6 15 / 5
9.3.5 15 / 5
9.3.4 15 / 5
9.3.3 15 / 5
9.3.2 15 / 5
9.3.1 15 / 5
9.3.0 15 / 5
9.2.1 15 / 5
9.2.0 14 / 6
9.1.0 14 / 6
9.0.1 14 / 6
9.0.0 14 / 6
8.7.3 14 / 6
8.7.2 14 / 6
8.7.1 14 / 6
8.7.0 14 / 6
8.6.1 14 / 6
8.6.0 14 / 6
8.5.1 14 / 6
8.5.0 14 / 6
8.4.3 14 / 6
8.4.2 14 / 6
8.4.1 14 / 6
8.4.0 14 / 6
8.3.0 14 / 6
8.2.4 14 / 6
8.2.3 14 / 6
8.2.2 14 / 6

v10.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v10.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.