@diplodoc/cli
Make documentation using yfm-docs in Markdown and HTML formats
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): New files are test snapshots and fixture images, not runtime code. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): postcss is declared as a runtime dep and used in config/build pipeline; phantom-dep heuristic is a false positive here. | ai | |
| dependencies | unvetted-dep:threads | AI (dependencies): [email protected] is a legitimate worker-threads abstraction library; stable usage in this build tool across many versions. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): yaml is a well-established package; addition is benign for this documentation tool. | ai | |
| source-diff | net-exec-file:assets/vendor-df2661ee19f97723.js | AI (source-diff): Webpack-bundled client asset; net-exec pattern is a false positive from bundled fetch polyfills and dynamic imports in the UI bundle. | ai | |
| source-diff | net-exec-file:assets/vendor-fefbbd2336b585a3.js | AI (source-diff): Webpack vendor chunk (cookie parsing, UI libs); standard bundled output, not a dropper. | ai | |
| phantom-deps | phantom-dep:@diplodoc/ajv | AI (phantom-deps): Same-org dep; phantom-dep pattern is consistent with other accepted phantom deps in this package. | ai | |
| source-diff | net-exec-file:assets/app-c3e8973ab1d89cc8.js | AI (source-diff): React app bundle with fetch/dynamic imports; expected pattern for this docs tool's frontend assets. | ai | |
| source-diff | obfuscated-file:assets/app-c3e8973ab1d89cc8.js | AI (source-diff): Standard webpack-minified frontend bundle for a docs CLI; not obfuscation. | ai | |
| source-diff | net-exec-file:assets/vendor-d233676225962abc.js | AI (source-diff): Webpack vendor bundle (cookie parsing, etc.); standard minified third-party code. | ai | |
| source-diff | obfuscated-file:assets/search-286bba91cb85430c.js | AI (source-diff): Webpack-minified search bundle; same pattern as other frontend assets in this package. | ai | |
| source-diff | obfuscated-file:assets/app-06661d5c25bbe373.js | AI (source-diff): Standard webpack-minified frontend bundle for diplodoc documentation viewer; not malware. | ai | |
| source-diff | net-exec-file:assets/vendor-d624c3b1cfc0a16a.js | AI (source-diff): Vendor bundle (cookie parsing, etc.) is normal webpack output for this documentation tool. | ai | |
| source-diff | net-exec-file:assets/app-06661d5c25bbe373.js | AI (source-diff): Network calls and dynamic code in webpack bundle are normal React app patterns, not dropper behavior. | ai | |
| source-diff | obfuscated-file:assets/search-d6011929331ae16f.js | AI (source-diff): Standard webpack-minified search bundle for diplodoc viewer. | ai | |
| source-diff | net-exec-file:assets/vendor-a301303071ab49a2.js | AI (source-diff): Vendor bundle (cookie parsing, webpack runtime); standard build artifact for this docs generator. | ai | |
| source-diff | obfuscated-file:assets/app-f86067fc0d7ffb1e.js | AI (source-diff): Standard webpack-minified React frontend bundle for docs viewer; consistent with diplodoc-platform/cli's documented build output. | ai | |
| source-diff | net-exec-file:assets/app-f86067fc0d7ffb1e.js | AI (source-diff): Network calls and dynamic code in webpack bundle are React/router patterns, not dropper behavior. | ai | |
| source-diff | obfuscated-file:assets/search-6389fee2cb71e580.js | AI (source-diff): Webpack-minified search UI bundle; same pattern as other frontend assets in this docs CLI. | ai | |
| source-diff | net-exec-file:assets/vendor-19f237a87f1f5fe7.js | AI (source-diff): Webpack-bundled frontend asset for a docs tool; sample shows standard cookie/module code, not malware. | ai | |
| phantom-deps | phantom-dep:@inquirer/prompts | AI (phantom-deps): Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:markdown-it-meta | AI (phantom-deps): Stable false positive for this docs toolchain. | ai | |
| phantom-deps | phantom-dep:markdown-it-sup | AI (phantom-deps): Stable false positive for this docs toolchain. | ai | |
| phantom-deps | phantom-dep:highlight.js | AI (phantom-deps): Stable false positive; bundled into frontend assets. | ai | |
| phantom-deps | phantom-dep:chroma-js | AI (phantom-deps): Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:threads | AI (phantom-deps): Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:katex | AI (phantom-deps): Stable false positive; bundled into frontend assets. | ai | |
| phantom-deps | phantom-dep:execa | AI (phantom-deps): Stable false positive for this docs toolchain package. | ai | |
| source-diff | net-exec-file:assets/vendor-b240c30f2bda07da.js | AI (source-diff): Webpack-bundled frontend assets for a docs CLI; network+eval pattern is standard bundler output, not malware. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require is inside requireExtension(), a documented plugin/extension loader — stable pattern for this package. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @diplodoc/cli is a documentation CLI; levenshtein match to 'joi' is a false positive with no brand overlap. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 5.49.4 | 31 / 46 | |
| 5.49.3 | 31 / 46 | |
| 5.49.1 | 31 / 46 | |
| 5.49.0 | 31 / 46 | |
| 5.48.2 | 30 / 47 | |
| 5.48.1 | 30 / 47 | |
| 5.48.0 | 30 / 47 | |
| 5.47.3 | 29 / 47 | |
| 5.47.1 | 29 / 47 | |
| 5.47.0 | 29 / 47 | |
| 5.46.1 | 29 / 46 | |
| 5.46.0 | 29 / 46 | |
| 5.45.0 | 28 / 46 | |
| 5.44.0 | 27 / 46 | |
| 5.43.3 | 27 / 46 | |
| 5.43.2 | 27 / 46 | |
| 5.43.0 | 27 / 46 | |
| 5.42.2 | 27 / 46 | |
| 5.42.1 | 27 / 46 | |
| 5.41.0 | 27 / 46 | |
| 5.39.7 | 27 / 45 | |
| 5.39.6 | 27 / 45 | |
| 5.39.4 | 27 / 45 | |
| 5.39.3 | 27 / 45 | |
| 5.39.2 | 27 / 45 | |
| 5.39.1 | 27 / 45 | |
| 5.39.0 | 27 / 45 | |
| 5.38.1 | 27 / 45 | |
| 5.37.1 | 27 / 45 | |
| 5.36.6 | 27 / 45 | |
| 5.36.4 | 27 / 45 | |
| 5.36.0 | 27 / 45 |
v5.49.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.49.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.49.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.49.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.48.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.48.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.48.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.47.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.43.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.