← Home

@lowdefy/blocks-markdown

Lowdefy markdown blocks.

14
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

samtolmaygervwykmachielvdw

Keywords

lowdefylowdefy blocksmarkdownreact-markdownlowdefy plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom is explicitly declared as a runtime dependency in package.json; phantom-dep heuristic misfires here. ai
provenance publisher-changed AI (provenance): Package publishes via GitHub Actions CI/CD with SLSA attestation; publisher-changed to GH Actions is expected for this org's release pipeline. ai

Versions (showing 14 of 14)

Version Deps Published
5.5.1 6 / 6
5.5.0 6 / 6
5.4.0 6 / 6
5.3.0 6 / 6
5.2.0 6 / 6
5.1.0 6 / 6
5.0.0 6 / 6
4.7.3 8 / 6
4.7.2 8 / 6
4.7.1 8 / 6
4.7.0 8 / 3
4.6.0 8 / 3
4.5.2 8 / 14
4.5.1 8 / 14

v5.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.