← Home

@mintlify/prebuild

Helpful functions for Mintlify's prebuild step

100
Versions
Elastic-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

dks333hanminthahnbeeshouchem-mintlifykylefinkenskeptrune

Keywords

mintlifymintprebuild

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@apidevtools/swagger-parser AI (phantom-deps): Likely used for types/parsing indirectly; established Mintlify package, low risk. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): Likely used in compiled dist output; benign for this well-established build helper package. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are Mintlify employees (ruhanponnada, kathrynmintlify, kylefinken); org-internal change. ai
provenance publisher-changed AI (provenance): Transition from individual account to GitHub Actions CI publishing; consistent with org CI/CD migration. ai
license uncommon-license:Elastic-2.0 AI (license): Elastic-2.0 is Mintlify's standard license across their packages. ai
phantom-deps phantom-dep:gray-matter AI (phantom-deps): gray-matter is referenced in config files but not directly imported; consistent with other accepted phantom deps in this package. ai
provenance no-provenance AI (provenance): Provenance attestation is uncommon across npm (~12%); absence is not a security disqualifier for this established package. ai
phantom-deps phantom-dep:openapi-types AI (phantom-deps): Legitimate types-only package; phantom detection expected for type-only imports in TypeScript projects. ai
dependencies unvetted-dep:favicons AI (dependencies): favicons is a well-known, legitimate favicon generation library; appropriate dependency for a documentation prebuild tool. ai
dependencies unvetted-dep:sharp-ico AI (dependencies): sharp-ico is a legitimate ICO format plugin for the sharp image library, which is also a direct dep; appropriate for favicon/image processing in prebuild. ai
phantom-deps phantom-dep:front-matter AI (phantom-deps): Legitimate package; phantom detection likely due to indirect/type-level usage in a TypeScript build context. ai
phantom-deps phantom-dep:unist-util-visit AI (phantom-deps): Legitimate unist utility; phantom detection likely due to indirect usage pattern in TypeScript build. ai
dependencies unvetted-dep:@mintlify/common AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. ai
phantom-deps phantom-dep:@mintlify/openapi-parser AI (phantom-deps): Same-org package; phantom dep finding is a code quality note, not a security risk for this package. ai
dependencies unvetted-dep:@mintlify/openapi-parser AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. ai
dependencies unvetted-dep:@mintlify/validation AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. ai
dependencies unvetted-dep:@mintlify/scraping AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. ai

Versions (showing 100 of 1191)

Version Deps Published
1.0.896 14 / 14
1.0.895 14 / 14
1.0.894 14 / 14
1.0.893 14 / 14
1.0.892 14 / 14
1.0.891 14 / 14
1.0.890 14 / 14
1.0.889 14 / 14
1.0.888 14 / 14
1.0.887 14 / 14
1.0.886 14 / 14
1.0.885 14 / 14
1.0.883 14 / 14
1.0.882 14 / 14
1.0.881 14 / 14
1.0.880 14 / 14
1.0.879 14 / 14
1.0.878 14 / 14
1.0.875 14 / 14
1.0.874 14 / 14
1.0.873 14 / 14
1.0.872 14 / 14
1.0.871 14 / 14
1.0.870 14 / 14
1.0.869 14 / 14
1.0.868 14 / 14
1.0.867 14 / 14
1.0.866 14 / 14
1.0.865 14 / 14
1.0.864 14 / 14
1.0.863 14 / 14
1.0.862 14 / 14
1.0.861 14 / 14
1.0.860 14 / 14
1.0.859 14 / 14
1.0.858 14 / 14
1.0.857 14 / 14
1.0.856 14 / 14
1.0.855 14 / 14
1.0.854 14 / 14
1.0.853 14 / 14
1.0.852 14 / 14
1.0.851 14 / 14
1.0.850 14 / 14
1.0.849 14 / 14
1.0.848 14 / 14
1.0.847 14 / 14
1.0.846 14 / 14
1.0.845 14 / 14
1.0.844 14 / 14
1.0.843 14 / 14
1.0.842 14 / 14
1.0.841 14 / 14
1.0.840 14 / 14
1.0.834 14 / 14
1.0.833 14 / 14
1.0.832 14 / 14
1.0.831 14 / 14
1.0.830 14 / 14
1.0.829 14 / 14
1.0.828 14 / 14
1.0.827 14 / 14
1.0.826 14 / 14
1.0.825 14 / 14
1.0.824 14 / 14
1.0.823 14 / 14
1.0.822 14 / 14
1.0.821 14 / 14
1.0.820 14 / 14
1.0.819 14 / 14
1.0.818 14 / 14
1.0.817 14 / 14
1.0.816 14 / 14
1.0.815 14 / 14
1.0.814 14 / 14
1.0.813 14 / 14
1.0.812 14 / 14
1.0.811 14 / 14
1.0.810 14 / 14
1.0.809 14 / 14
1.0.808 14 / 14
1.0.807 14 / 14
1.0.806 14 / 14
1.0.805 14 / 14
1.0.804 14 / 14
1.0.803 14 / 14
1.0.802 14 / 14
1.0.801 14 / 14
1.0.800 14 / 14
1.0.799 14 / 14
1.0.798 14 / 14
1.0.797 14 / 14
1.0.796 14 / 14
1.0.795 14 / 14
1.0.794 14 / 14
1.0.793 14 / 14
1.0.792 14 / 14
1.0.791 14 / 14
1.0.790 14 / 14
1.0.789 14 / 14
Showing 100 of 1191 Next page →

v1.0.885

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.875

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.