← Home

@forsakringskassan/docs-generator

Documentation generator

12
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

extfk-jonatan-haqgglundtomasbjerreoloff

Keywords

documentation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/vendor-DLyCCfC4.mjs AI (source-diff): Large bundled vendor file with source map; imports are standard Node built-ins consistent with a docs generator tool, not malware. ai
source-diff net-exec-file:dist/vendor-CyiP4ufo.mjs AI (source-diff): Vite-bundled vendor chunk for a docs generator; Node built-in imports are expected, not dropper behavior. ai
source-diff net-exec-file:dist/vendor-C0JAkCK-.mjs AI (source-diff): Large Vite/Rollup vendor bundle for a docs-generator tool; Node built-in imports are expected, not malicious. ai
source-diff net-exec-file:dist/vendor-B7bJ2okl.mjs AI (source-diff): Standard Vite/Rollup vendor bundle; network imports are Node built-ins (http/https), not external fetches. Pattern is stable for this docs-generator package. ai
source-diff net-exec-file:dist/vendor-BoRn-ubH.mjs AI (source-diff): Vite-bundled vendor chunk for a docs-generator; network imports are livereload/dev-server tooling, not dropper behavior. SLSA provenance confirms CI build. ai
source-diff net-exec-file:dist/vendor-DX88DJvo.mjs AI (source-diff): Large vendor bundle is standard Vite/Rollup output for a docs-generator; node built-in imports are expected, not malicious. ai
source-diff net-exec-file:dist/vendor-BhMQq6vU.mjs AI (source-diff): Large vendor bundle from Vite/Rollup build; imports are Node built-ins consistent with docs-generator tooling, not malware. ai
phantom-deps phantom-dep:@fontsource-variable/inter AI (phantom-deps): Font asset referenced in build config, not directly imported in JS — stable false positive. ai
phantom-deps phantom-dep:livereload-js AI (phantom-deps): Asset dependency referenced in build config, not directly imported in JS — stable false positive. ai
publish-pattern dormant-publish AI (publish-pattern): Package has 145 versions and SLSA provenance; dormancy flag is a false positive for this active project. ai
source-diff net-exec-file:dist/vendor-tIJeYoyt.mjs AI (source-diff): Standard Vite vendor bundle for a docs-generator; imports are Node built-ins and bundled deps, not malware. ai

Versions (showing 12 of 12)

Version Deps Published
3.0.3 9 / 0
3.0.2 9 / 0
3.0.1 9 / 0
3.0.0 9 / 0
2.43.0 9 / 0
2.42.0 7 / 0
2.41.1 7 / 0
2.41.0 7 / 0
2.40.3 7 / 0
2.40.2 7 / 0
2.40.1 7 / 0
2.40.0 7 / 0

v3.0.3

2 findings
HIGH New file with network + code execution: dist/vendor-DLyCCfC4.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.2

2 findings
HIGH New file with network + code execution: dist/vendor-CyiP4ufo.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.1

2 findings
HIGH New file with network + code execution: dist/vendor-C0JAkCK-.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.0

2 findings
HIGH New file with network + code execution: dist/vendor-B7bJ2okl.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.43.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.42.0

2 findings
HIGH New file with network + code execution: dist/vendor-BoRn-ubH.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.41.1

2 findings
HIGH New file with network + code execution: dist/vendor-DX88DJvo.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.41.0

2 findings
HIGH New file with network + code execution: dist/vendor-BhMQq6vU.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.40.3

2 findings
HIGH New file with network + code execution: dist/vendor-tIJeYoyt.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.40.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.40.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.40.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.