@aiou/remark-config
[](https://github.com/neo-hack/remark-config) [](https://github.com/neo-hack/remark-config) [ relied on exactly this gap.
Maintainers
qidanta
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:retext-quotes | AI (dependencies): Established unified/retext ecosystem plugin; not a security risk. | ai | |
| dependencies | unvetted-dep:retext-contractions | AI (dependencies): Established unified/retext ecosystem plugin; not a security risk. | ai | |
| dependencies | unvetted-dep:remark-comment-config | AI (dependencies): Established remark ecosystem plugin; not a security risk. | ai | |
| dependencies | unvetted-dep:retext-repeated-words | AI (dependencies): Established unified/retext ecosystem plugin; not a security risk. | ai | |
| dependencies | unvetted-dep:retext-sentence-spacing | AI (dependencies): Established unified/retext ecosystem plugin; not a security risk. | ai | |
| dependencies | unvetted-dep:remark-lint-no-empty-url | AI (dependencies): Established remark-lint plugin; not a security risk. | ai | |
| dependencies | unvetted-dep:retext-indefinite-article | AI (dependencies): Established unified/retext ecosystem plugin; not a security risk. | ai | |
| dependencies | unvetted-dep:remark-lint-spaces-around-word | AI (dependencies): Remark-lint plugin consistent with package purpose; not a security risk. | ai | |
| dependencies | unvetted-dep:remark-lint-spaces-around-number | AI (dependencies): Remark-lint plugin consistent with package purpose; not a security risk. | ai | |
| dependencies | unvetted-dep:remark-lint-no-missing-blank-lines | AI (dependencies): Established remark-lint plugin; not a security risk. | ai | |
| dependencies | unvetted-dep:remark-lint-no-heading-like-paragraph | AI (dependencies): Established remark-lint plugin; not a security risk. | ai | |
| dependencies | unvetted-dep:remark-lint-no-duplicate-headings-in-section | AI (dependencies): Established remark-lint plugin; not a security risk. | ai | |
| phantom-deps | phantom-dep:remark-preset-lint-recommended | AI (phantom-deps): Listed as runtime dep in package.json; phantom-dep heuristic false positive for config-style packages. | ai |
Versions (showing 1 of 1)
| Version | Deps | Published |
|---|---|---|
| 0.2.0 | 37 / 30 |
v0.2.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.