← Home

@elliemae/pui-doc-gen

Documentation Site Generator

4
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

encw.dev

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@tsconfig/docusaurus AI (dependencies): Well-known Docusaurus ecosystem tsconfig package; stable false positive for this doc-gen tool. ai
dependencies unvetted-dep:docusaurus-plugin-typedoc AI (dependencies): Standard Docusaurus/TypeDoc integration plugin; expected dependency for a doc-gen package. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Docusaurus peer dep loaded by framework convention. ai
phantom-deps phantom-dep:@types/react AI (phantom-deps): Type-only package loaded by convention; not directly imported. ai
phantom-deps phantom-dep:@mdx-js/react AI (phantom-deps): Docusaurus config-referenced dep; not directly imported by design. ai
phantom-deps phantom-dep:@docusaurus/core AI (phantom-deps): Docusaurus config-referenced dep; not directly imported by design. ai
phantom-deps phantom-dep:@types/react-dom AI (phantom-deps): Type-only package loaded by convention; not directly imported. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): Docusaurus config-referenced dep; not directly imported by design. ai
phantom-deps phantom-dep:typedoc-plugin-markdown AI (phantom-deps): Docusaurus plugin loaded by config; not directly imported. ai
phantom-deps phantom-dep:@docusaurus/theme-mermaid AI (phantom-deps): Docusaurus theme loaded by config; not directly imported. ai
phantom-deps phantom-dep:docusaurus-plugin-typedoc AI (phantom-deps): Docusaurus plugin loaded by config; not directly imported. ai
phantom-deps phantom-dep:@docusaurus/preset-classic AI (phantom-deps): Docusaurus preset loaded by config; not directly imported. ai
phantom-deps phantom-dep:@docusaurus/module-type-aliases AI (phantom-deps): Type alias package loaded by convention; not directly imported. ai
phantom-deps phantom-dep:@tsconfig/docusaurus AI (phantom-deps): TSConfig extension; not directly imported by design. ai
phantom-deps phantom-dep:react AI (phantom-deps): Docusaurus peer dep loaded by framework convention. ai

Versions (showing 4 of 4)

Version Deps Published
3.8.0 16 / 6
3.7.2 14 / 6
3.7.1 14 / 6
3.6.0 13 / 6

v3.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.