← Home

@codingame/monaco-vscode-mermaid-markdown-features-default-extension

13
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

nonofrsamuel.oliviernantoniazzimaximecgcodingame_team

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:resources/extension.js AI (source-diff): Standard minified VS Code extension bundle; expected for this package's build pipeline. ai
source-diff obfuscated-file:resources/index-editor.js AI (source-diff): Standard minified VS Code extension bundle; expected for this package's build pipeline. ai
source-diff obfuscated-file:resources/index.js AI (source-diff): Standard minified VS Code extension bundle; expected for this package's build pipeline. ai
source-diff obfuscated-file:index.js AI (source-diff): Standard minified VS Code extension bundle; expected for this package's build pipeline. ai
source-diff net-exec-file:resources/index-editor.js AI (source-diff): Network calls are VS Code webview fetch patterns; dynamic code execution is standard bundler output, not malware. ai
source-diff net-exec-file:resources/index.js AI (source-diff): Network calls are VS Code webview fetch patterns; dynamic code execution is standard bundler output, not malware. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher with SLSA provenance is a legitimate CI/CD migration, not a compromise. ai

Versions (showing 13 of 13)

Version Deps Published
35.0.3 1 / 0
35.0.2 1 / 0
35.0.1 1 / 0
35.0.0 1 / 0
34.1.3 1 / 0
34.1.1 1 / 0
34.0.3 1 / 0
34.0.2 1 / 0
34.0.1 1 / 0
34.0.0 1 / 0
33.0.9 1 / 0
33.0.7 1 / 0
0.0.1 0 / 0

v35.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v35.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v34.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.