@jupyterlab/rendermime
JupyterLab - RenderMime
3
Versions
BSD-3-Clause
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
darianjasongroutjtpiokrassowskijupyterlab-release-bot
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@phosphor/algorithm | AI (phantom-deps): Phosphor framework package referenced in config files; standard JupyterLab dependency pattern. | ai | |
| phantom-deps | phantom-dep:@phosphor/disposable | AI (phantom-deps): Phosphor framework package referenced in config files; standard JupyterLab dependency pattern. | ai | |
| provenance | no-provenance | AI (provenance): Long-established JupyterLab monorepo package predating Sigstore provenance adoption on npm; no provenance is expected for this era of publishing. | ai | |
| dependencies | unvetted-dep:ansi_up | AI (dependencies): ansi_up is a legitimate, widely-used ANSI escape code parser; its use in JupyterLab rendermime is expected and appropriate. | ai | |
| phantom-deps | phantom-dep:@types/marked | AI (phantom-deps): @types/marked is a TypeScript type declaration package; declaring it as a dependency without direct imports is standard TypeScript practice for this package. | ai | |
| phantom-deps | phantom-dep:@types/mathjax | AI (phantom-deps): @types/mathjax is a TypeScript type declaration package; declaring it as a dependency without direct imports is standard TypeScript practice for this package. | ai | |
| dependencies | unvetted-dep:@jupyterlab/apputils | AI (dependencies): Official JupyterLab monorepo sub-package; no security concerns. | ai | |
| dependencies | unvetted-dep:@jupyterlab/nbformat | AI (dependencies): Official JupyterLab monorepo sub-package; no security concerns. | ai | |
| dependencies | unvetted-dep:@jupyterlab/services | AI (dependencies): Official JupyterLab monorepo sub-package; no security concerns. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo sub-package of JupyterLab; inflated semver, short README, and no keywords are expected for automated monorepo releases. SLSA provenance confirms legitimacy. | ai | |
| dependencies | unvetted-dep:@jupyterlab/observables | AI (dependencies): Official JupyterLab monorepo sub-package; no security concerns. | ai | |
| dependencies | unvetted-dep:@jupyterlab/translation | AI (dependencies): Official JupyterLab monorepo sub-package; no security concerns. | ai | |
| dependencies | unvetted-dep:@jupyterlab/rendermime-interfaces | AI (dependencies): Official JupyterLab monorepo sub-package; no security concerns. | ai | |
| dependencies | unvetted-dep:@jupyterlab/coreutils | AI (dependencies): Official JupyterLab monorepo sub-package; no security concerns. | ai | |
| dependencies | unvetted-dep:lodash.escape | AI (dependencies): lodash.escape is a well-known, widely-used utility package with no security concerns relevant to this context. | ai | |
| dependencies | unvetted-dep:@lumino/widgets | AI (dependencies): Canonical Lumino UI framework package maintained by Project Jupyter; no security concerns. | ai | |
| dependencies | unvetted-dep:@lumino/coreutils | AI (dependencies): Canonical Lumino package maintained by Project Jupyter; no security concerns. | ai | |
| dependencies | unvetted-dep:@lumino/messaging | AI (dependencies): Canonical Lumino package maintained by Project Jupyter; no security concerns. | ai | |
| dependencies | unvetted-dep:@lumino/signaling | AI (dependencies): Canonical Lumino package maintained by Project Jupyter; no security concerns. | ai |