← Home

@diplodoc/cli

Make documentation using yfm-docs in Markdown and HTML formats

32
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

rndnmrobot-dataui-npmalexey_w1003y3martyanov-avvseshmakhnatkindiplodoc-botreazy015goldsergseparatrix

Keywords

markdownyandexdocsyfmdocumentationtooltoolsgenerator

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): New files are test snapshots and fixture images, not runtime code. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): postcss is declared as a runtime dep and used in config/build pipeline; phantom-dep heuristic is a false positive here. ai
dependencies unvetted-dep:threads AI (dependencies): [email protected] is a legitimate worker-threads abstraction library; stable usage in this build tool across many versions. ai
publish-pattern new-deps-added AI (publish-pattern): yaml is a well-established package; addition is benign for this documentation tool. ai
source-diff net-exec-file:assets/vendor-df2661ee19f97723.js AI (source-diff): Webpack-bundled client asset; net-exec pattern is a false positive from bundled fetch polyfills and dynamic imports in the UI bundle. ai
source-diff net-exec-file:assets/vendor-fefbbd2336b585a3.js AI (source-diff): Webpack vendor chunk (cookie parsing, UI libs); standard bundled output, not a dropper. ai
phantom-deps phantom-dep:@diplodoc/ajv AI (phantom-deps): Same-org dep; phantom-dep pattern is consistent with other accepted phantom deps in this package. ai
source-diff net-exec-file:assets/app-c3e8973ab1d89cc8.js AI (source-diff): React app bundle with fetch/dynamic imports; expected pattern for this docs tool's frontend assets. ai
source-diff obfuscated-file:assets/app-c3e8973ab1d89cc8.js AI (source-diff): Standard webpack-minified frontend bundle for a docs CLI; not obfuscation. ai
source-diff net-exec-file:assets/vendor-d233676225962abc.js AI (source-diff): Webpack vendor bundle (cookie parsing, etc.); standard minified third-party code. ai
source-diff obfuscated-file:assets/search-286bba91cb85430c.js AI (source-diff): Webpack-minified search bundle; same pattern as other frontend assets in this package. ai
source-diff obfuscated-file:assets/app-06661d5c25bbe373.js AI (source-diff): Standard webpack-minified frontend bundle for diplodoc documentation viewer; not malware. ai
source-diff net-exec-file:assets/vendor-d624c3b1cfc0a16a.js AI (source-diff): Vendor bundle (cookie parsing, etc.) is normal webpack output for this documentation tool. ai
source-diff net-exec-file:assets/app-06661d5c25bbe373.js AI (source-diff): Network calls and dynamic code in webpack bundle are normal React app patterns, not dropper behavior. ai
source-diff obfuscated-file:assets/search-d6011929331ae16f.js AI (source-diff): Standard webpack-minified search bundle for diplodoc viewer. ai
source-diff net-exec-file:assets/vendor-a301303071ab49a2.js AI (source-diff): Vendor bundle (cookie parsing, webpack runtime); standard build artifact for this docs generator. ai
source-diff obfuscated-file:assets/app-f86067fc0d7ffb1e.js AI (source-diff): Standard webpack-minified React frontend bundle for docs viewer; consistent with diplodoc-platform/cli's documented build output. ai
source-diff net-exec-file:assets/app-f86067fc0d7ffb1e.js AI (source-diff): Network calls and dynamic code in webpack bundle are React/router patterns, not dropper behavior. ai
source-diff obfuscated-file:assets/search-6389fee2cb71e580.js AI (source-diff): Webpack-minified search UI bundle; same pattern as other frontend assets in this docs CLI. ai
source-diff net-exec-file:assets/vendor-19f237a87f1f5fe7.js AI (source-diff): Webpack-bundled frontend asset for a docs tool; sample shows standard cookie/module code, not malware. ai
phantom-deps phantom-dep:@inquirer/prompts AI (phantom-deps): Stable false positive for this package. ai
phantom-deps phantom-dep:markdown-it-meta AI (phantom-deps): Stable false positive for this docs toolchain. ai
phantom-deps phantom-dep:markdown-it-sup AI (phantom-deps): Stable false positive for this docs toolchain. ai
phantom-deps phantom-dep:highlight.js AI (phantom-deps): Stable false positive; bundled into frontend assets. ai
phantom-deps phantom-dep:chroma-js AI (phantom-deps): Stable false positive for this package. ai
phantom-deps phantom-dep:threads AI (phantom-deps): Stable false positive for this package. ai
phantom-deps phantom-dep:katex AI (phantom-deps): Stable false positive; bundled into frontend assets. ai
phantom-deps phantom-dep:execa AI (phantom-deps): Stable false positive for this docs toolchain package. ai
source-diff net-exec-file:assets/vendor-b240c30f2bda07da.js AI (source-diff): Webpack-bundled frontend assets for a docs CLI; network+eval pattern is standard bundler output, not malware. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require is inside requireExtension(), a documented plugin/extension loader — stable pattern for this package. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @diplodoc/cli is a documentation CLI; levenshtein match to 'joi' is a false positive with no brand overlap. ai

Versions (showing 32 of 32)

Version Deps Published
5.49.4 31 / 46
5.49.3 31 / 46
5.49.1 31 / 46
5.49.0 31 / 46
5.48.2 30 / 47
5.48.1 30 / 47
5.48.0 30 / 47
5.47.3 29 / 47
5.47.1 29 / 47
5.47.0 29 / 47
5.46.1 29 / 46
5.46.0 29 / 46
5.45.0 28 / 46
5.44.0 27 / 46
5.43.3 27 / 46
5.43.2 27 / 46
5.43.0 27 / 46
5.42.2 27 / 46
5.42.1 27 / 46
5.41.0 27 / 46
5.39.7 27 / 45
5.39.6 27 / 45
5.39.4 27 / 45
5.39.3 27 / 45
5.39.2 27 / 45
5.39.1 27 / 45
5.39.0 27 / 45
5.38.1 27 / 45
5.37.1 27 / 45
5.36.6 27 / 45
5.36.4 27 / 45
5.36.0 27 / 45

v5.49.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.49.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.49.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.49.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.48.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.48.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.48.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.47.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.43.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.