← Home

@jupyterlab/toc

JupyterLab - Table of Contents widget

37
Versions
BSD-3-Clause
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

darianblink1073jasongroutfcollonvaljtpiombektaskrassowskijupyterlab-release-bot

Keywords

jupyterlab

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): All new deps are canonical JupyterLab/Lumino ecosystem packages. The diff is cross-major-version (5.x vs 6.x), making dependency differences expected and benign for this package. ai
source-diff large-new-source-files AI (source-diff): Cross-major-version diff (5.x vs 6.x) naturally produces large file count differences. Package has SLSA provenance and is published by the official JupyterLab release bot. ai
dependencies unvetted-dep:@jupyter/react-components AI (dependencies): @jupyter/react-components is an official Jupyter project package under the @jupyter scope, consistent with JupyterLab's ecosystem. Not a suspicious dependency. ai
dependencies unvetted-dep:@jupyterlab/markdownviewer AI (dependencies): @jupyterlab/markdownviewer is a first-party JupyterLab package from the same monorepo, published by the same trusted jupyterlab-release-bot. Stable accept for this package. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Clearly not a typosquat; @jupyterlab/toc is a scoped official JupyterLab package with nearly 3000 days of history. ai
typosquat typosquat.levenshtein:got AI (typosquat): Clearly not a typosquat; @jupyterlab/toc is a scoped official JupyterLab package with nearly 3000 days of history. ai
typosquat typosquat.levenshtein:koa AI (typosquat): Clearly not a typosquat; @jupyterlab/toc is a scoped official JupyterLab package with nearly 3000 days of history. ai
bogus-package bogus-package AI (bogus-package): False positive: @jupyterlab/toc has 2828 days of history and 318 versions. Inflated semver and short README signals do not apply to this long-established package. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Clearly not a typosquat; @jupyterlab/toc is a scoped official JupyterLab package with nearly 3000 days of history. ai

Versions (showing 37 of 137)

Version Deps Published
5.1.12 18 / 11
5.1.11 18 / 11
5.1.10 18 / 11
5.1.9 18 / 11
5.1.8 18 / 11
5.1.7 18 / 11
5.1.6 18 / 11
5.1.5 18 / 11
5.1.4 18 / 11
5.1.3 18 / 11
5.1.2 18 / 11
5.1.1 18 / 11
5.1.0 18 / 11
5.0.14 17 / 10
5.0.13 17 / 10
5.0.12 17 / 10
5.0.11 17 / 10
5.0.10 17 / 10
5.0.9 17 / 10
5.0.8 17 / 10
5.0.7 17 / 10
5.0.6 17 / 10
5.0.5 17 / 10
5.0.4 17 / 10
5.0.3 17 / 10
5.0.2 17 / 10
5.0.1 17 / 10
5.0.0 17 / 10
4.0.0 16 / 10
3.0.0 16 / 10
2.0.0 16 / 10
1.0.1 16 / 10
0.6.0 15 / 10
0.5.0 15 / 10
0.4.0 15 / 10
0.3.1 15 / 10
0.3.0 15 / 10

v5.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.