@docusaurus/utils-validation
Node validation utility functions for Docusaurus packages.
34
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
fbslorberlex111docusaurus-bot
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Docusaurus monorepo transitioned to GitHub Actions CI/CD publishing, corroborated by SLSA provenance attestation. This is a legitimate and expected supply chain improvement for the facebook/docusaurus project. | ai | |
| dependencies | unvetted-dep:joi | AI (dependencies): joi is a well-known, widely-used validation library; its use is expected and appropriate for a validation utility package in the Docusaurus ecosystem. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal monorepo utility package from facebook/docusaurus; sparse README and no keywords are expected for packages not intended for independent discovery. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 3.10.2 | 8 / 1 | |
| 3.10.1 | 8 / 1 | |
| 3.10.0 | 8 / 1 | |
| 3.9.2 | 8 / 1 | |
| 3.9.1 | 8 / 1 | |
| 3.9.0 | 8 / 1 | |
| 3.8.1 | 8 / 1 | |
| 3.8.0 | 8 / 1 | |
| 3.7.0 | 8 / 1 | |
| 3.6.3 | 8 / 1 | |
| 3.6.2 | 8 / 1 | |
| 3.6.1 | 8 / 1 | |
| 3.6.0 | 8 / 1 | |
| 3.5.2 | 8 / 1 | |
| 3.5.1 | 8 / 1 | |
| 3.5.0 | 8 / 1 | |
| 3.4.0 | 8 / 1 | |
| 3.3.2 | 6 / 0 | |
| 3.3.0 | 6 / 0 | |
| 3.2.1 | 6 / 0 | |
| 3.2.0 | 6 / 0 | |
| 3.1.1 | 5 / 0 | |
| 3.1.0 | 5 / 0 | |
| 3.0.1 | 5 / 0 | |
| 3.0.0 | 5 / 0 | |
| 2.4.3 | 5 / 0 | |
| 2.4.1 | 5 / 0 | |
| 2.4.0 | 5 / 0 | |
| 2.3.1 | 5 / 0 | |
| 2.3.0 | 5 / 0 | |
| 2.2.0 | 5 / 0 | |
| 2.1.0 | 5 / 0 | |
| 2.0.1 | 5 / 0 | |
| 2.0.0 | 5 / 0 |
v3.10.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.