@box/box-ai-content-answers
<!-- START doctoc generated TOC please keep comment here to allow auto update --> <!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/chunks/markdown.js | AI (source-diff): Minified bundler output inlining highlight.js/remarkable; consistent with declared deps and Box's build pipeline. | ai |
Versions (showing 100 of 346)
| Version | Deps | Published |
|---|---|---|
| 1.43.25 | 2 / 11 | |
| 1.43.24 | 2 / 11 | |
| 1.43.23 | 2 / 11 | |
| 1.43.22 | 2 / 11 | |
| 1.43.21 | 2 / 11 | |
| 1.43.20 | 2 / 11 | |
| 1.43.19 | 2 / 11 | |
| 1.43.18 | 2 / 11 | |
| 1.43.17 | 2 / 11 | |
| 1.43.16 | 2 / 11 | |
| 1.43.15 | 2 / 11 | |
| 1.43.14 | 2 / 11 | |
| 1.43.13 | 2 / 11 | |
| 1.43.12 | 2 / 11 | |
| 1.43.11 | 2 / 11 | |
| 1.43.10 | 2 / 11 | |
| 1.43.9 | 2 / 10 | |
| 1.43.8 | 2 / 10 | |
| 1.43.7 | 2 / 10 | |
| 1.43.6 | 2 / 10 | |
| 1.43.5 | 2 / 10 | |
| 1.43.4 | 2 / 10 | |
| 1.43.3 | 2 / 10 | |
| 1.43.2 | 2 / 10 | |
| 1.43.1 | 2 / 10 | |
| 1.43.0 | 2 / 10 | |
| 1.42.44 | 2 / 10 | |
| 1.42.43 | 2 / 10 | |
| 1.42.42 | 2 / 10 | |
| 1.42.41 | 2 / 10 | |
| 1.42.40 | 2 / 10 | |
| 1.42.39 | 2 / 10 | |
| 1.42.38 | 2 / 10 | |
| 1.42.37 | 2 / 10 | |
| 1.42.36 | 2 / 10 | |
| 1.42.35 | 2 / 10 | |
| 1.42.34 | 2 / 10 | |
| 1.42.33 | 2 / 10 | |
| 1.42.32 | 2 / 10 | |
| 1.42.31 | 2 / 10 | |
| 1.42.30 | 2 / 10 | |
| 1.42.29 | 2 / 10 | |
| 1.42.28 | 2 / 10 | |
| 1.42.27 | 2 / 10 | |
| 1.42.26 | 2 / 10 | |
| 1.42.25 | 2 / 10 | |
| 1.42.24 | 2 / 10 | |
| 1.42.23 | 2 / 10 | |
| 1.42.22 | 2 / 10 | |
| 1.42.21 | 2 / 10 | |
| 1.42.20 | 2 / 10 | |
| 1.42.19 | 2 / 10 | |
| 1.42.18 | 2 / 10 | |
| 1.42.17 | 2 / 10 | |
| 1.42.16 | 2 / 10 | |
| 1.42.15 | 2 / 10 | |
| 1.42.14 | 2 / 10 | |
| 1.42.13 | 2 / 10 | |
| 1.42.12 | 2 / 10 | |
| 1.42.11 | 2 / 10 | |
| 1.42.10 | 2 / 10 | |
| 1.42.9 | 2 / 10 | |
| 1.42.8 | 2 / 10 | |
| 1.42.7 | 2 / 10 | |
| 1.42.6 | 2 / 10 | |
| 1.42.5 | 2 / 10 | |
| 1.42.4 | 2 / 10 | |
| 1.42.3 | 2 / 10 | |
| 1.42.2 | 2 / 10 | |
| 1.42.1 | 2 / 10 | |
| 1.42.0 | 2 / 10 | |
| 1.41.1 | 2 / 10 | |
| 1.41.0 | 2 / 10 | |
| 1.40.2 | 2 / 10 | |
| 1.40.1 | 2 / 10 | |
| 1.40.0 | 2 / 10 | |
| 1.39.2 | 2 / 10 | |
| 1.39.1 | 2 / 10 | |
| 1.39.0 | 2 / 10 | |
| 1.38.2 | 2 / 10 | |
| 1.38.1 | 2 / 10 | |
| 1.38.0 | 2 / 10 | |
| 1.37.0 | 2 / 10 | |
| 1.36.2 | 2 / 10 | |
| 1.36.1 | 2 / 10 | |
| 1.36.0 | 2 / 10 | |
| 1.35.2 | 2 / 10 | |
| 1.35.1 | 2 / 10 | |
| 1.35.0 | 2 / 10 | |
| 1.34.4 | 2 / 10 | |
| 1.34.3 | 2 / 10 | |
| 1.34.2 | 2 / 10 | |
| 1.34.1 | 2 / 10 | |
| 1.34.0 | 2 / 10 | |
| 1.33.0 | 2 / 10 | |
| 1.32.2 | 2 / 10 | |
| 1.32.1 | 2 / 10 | |
| 1.32.0 | 2 / 10 | |
| 1.31.5 | 2 / 10 | |
| 1.31.4 | 2 / 10 |
v1.43.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.43.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.44
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.42
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.42.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.41.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.41.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.40.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.39.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.38.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.37.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.36.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.35.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.34.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.33.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.32.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.31.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.31.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.