← Home

@idan_ariav/qmd

Query Markup Documents - On-device hybrid search for markdown files with BM25, vector search, and LLM reranking

5
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

idan_ariav

Keywords

markdownsearchftsfull-text-searchvectorsemantic-searchsqlitebm25embeddingsragmcprerankingknowledge-baselocal-aillm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped package under author's own namespace; unrelated to qs, not a typosquat. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Scoped package under author's own namespace; unrelated to zod, not a typosquat. ai
phantom-deps phantom-dep:@types/mdast AI (phantom-deps): @types/mdast is a type-only dependency used by remark/unified ecosystem; stable false positive. ai

Versions (showing 5 of 5)

Version Deps Published
2.4.0 14 / 5
2.3.1 14 / 5
2.3.0 14 / 5
2.2.0 14 / 4
2.1.0 14 / 4

v2.4.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: idan_ariav → GitHub Actions (on 2026-07-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (idan_ariav) on 2026-07-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.