postcss-color-gray
Use the gray() color function in CSS
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Package transferred to jonathantneal under the official postcss GitHub org. Transition is documented and jonathantneal is a highly trusted PostCSS ecosystem maintainer (677 approved packages, 0 rejected). | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy aligns with the maintainer transition and major rewrite. New publisher is a well-established, trusted npm contributor. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by Rollup bundling (pretest script runs rollup). Package now ships pre-bundled CJS and ES module outputs rather than unbundled source. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 5.0.0 | 3 / 9 | |
| 4.1.0 | 4 / 5 | |
| 4.0.0 | 4 / 6 | |
| 3.0.1 | 4 / 7 | |
| 3.0.0 | 4 / 6 | |
| 2.0.0 | 3 / 7 | |
| 1.1.0 | 3 / 7 | |
| 1.0.0 | 2 / 7 | |
| 0.1.0 | 2 / 7 | |
| 0.0.0 | 2 / 7 |
v5.0.0
2 findingsThis version was published by a different npm account than previous versions on 2018-10-10. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2017-12-19. This could indicate a legitimate maintainer transition or an account compromise.
v4.0.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2017-05-15. This could indicate a legitimate maintainer transition or an account compromise.