← Home

@mintlify/prebuild

Helpful functions for Mintlify's prebuild step

100
Versions
Elastic-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

dks333hanminthahnbeeshouchem-mintlifykylefinkenskeptrune

Keywords

mintlifymintprebuild

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@apidevtools/swagger-parser AI (phantom-deps): Likely used for types/parsing indirectly; established Mintlify package, low risk. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): Likely used in compiled dist output; benign for this well-established build helper package. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are Mintlify employees (ruhanponnada, kathrynmintlify, kylefinken); org-internal change. ai
provenance publisher-changed AI (provenance): Transition from individual account to GitHub Actions CI publishing; consistent with org CI/CD migration. ai
license uncommon-license:Elastic-2.0 AI (license): Elastic-2.0 is Mintlify's standard license across their packages. ai
phantom-deps phantom-dep:gray-matter AI (phantom-deps): gray-matter is referenced in config files but not directly imported; consistent with other accepted phantom deps in this package. ai
provenance no-provenance AI (provenance): Provenance attestation is uncommon across npm (~12%); absence is not a security disqualifier for this established package. ai
phantom-deps phantom-dep:openapi-types AI (phantom-deps): Legitimate types-only package; phantom detection expected for type-only imports in TypeScript projects. ai
dependencies unvetted-dep:favicons AI (dependencies): favicons is a well-known, legitimate favicon generation library; appropriate dependency for a documentation prebuild tool. ai
dependencies unvetted-dep:sharp-ico AI (dependencies): sharp-ico is a legitimate ICO format plugin for the sharp image library, which is also a direct dep; appropriate for favicon/image processing in prebuild. ai
phantom-deps phantom-dep:front-matter AI (phantom-deps): Legitimate package; phantom detection likely due to indirect/type-level usage in a TypeScript build context. ai
phantom-deps phantom-dep:unist-util-visit AI (phantom-deps): Legitimate unist utility; phantom detection likely due to indirect usage pattern in TypeScript build. ai
dependencies unvetted-dep:@mintlify/common AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. ai
phantom-deps phantom-dep:@mintlify/openapi-parser AI (phantom-deps): Same-org package; phantom dep finding is a code quality note, not a security risk for this package. ai
dependencies unvetted-dep:@mintlify/openapi-parser AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. ai
dependencies unvetted-dep:@mintlify/validation AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. ai
dependencies unvetted-dep:@mintlify/scraping AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. ai

Versions (showing 100 of 1191)

Version Deps Published
1.0.996 14 / 14
1.0.995 14 / 14
1.0.994 14 / 14
1.0.993 14 / 14
1.0.992 14 / 14
1.0.991 14 / 14
1.0.990 14 / 14
1.0.989 14 / 14
1.0.988 14 / 14
1.0.987 14 / 14
1.0.986 14 / 14
1.0.985 14 / 14
1.0.984 14 / 14
1.0.983 14 / 14
1.0.982 14 / 14
1.0.981 14 / 14
1.0.980 14 / 14
1.0.979 14 / 14
1.0.978 14 / 14
1.0.977 14 / 14
1.0.976 14 / 14
1.0.975 14 / 14
1.0.974 14 / 14
1.0.973 14 / 14
1.0.972 14 / 14
1.0.971 14 / 14
1.0.970 14 / 14
1.0.969 14 / 14
1.0.968 14 / 14
1.0.967 14 / 14
1.0.966 14 / 14
1.0.965 14 / 14
1.0.964 14 / 14
1.0.963 14 / 14
1.0.962 14 / 14
1.0.961 14 / 14
1.0.960 14 / 14
1.0.959 14 / 14
1.0.958 14 / 14
1.0.957 14 / 14
1.0.956 14 / 14
1.0.955 14 / 14
1.0.954 14 / 14
1.0.953 14 / 14
1.0.952 14 / 14
1.0.951 14 / 14
1.0.950 14 / 14
1.0.949 14 / 14
1.0.948 14 / 14
1.0.947 14 / 14
1.0.946 14 / 14
1.0.945 14 / 14
1.0.944 14 / 14
1.0.943 14 / 14
1.0.942 14 / 14
1.0.941 14 / 14
1.0.940 14 / 14
1.0.939 14 / 14
1.0.938 14 / 14
1.0.937 14 / 14
1.0.936 14 / 14
1.0.935 14 / 14
1.0.934 14 / 14
1.0.933 14 / 14
1.0.932 14 / 14
1.0.931 14 / 14
1.0.930 14 / 14
1.0.929 14 / 14
1.0.928 14 / 14
1.0.927 14 / 14
1.0.926 14 / 14
1.0.925 14 / 14
1.0.924 14 / 14
1.0.923 14 / 14
1.0.922 14 / 14
1.0.921 14 / 14
1.0.920 14 / 14
1.0.919 14 / 14
1.0.918 14 / 14
1.0.917 14 / 14
1.0.916 14 / 14
1.0.915 14 / 14
1.0.914 14 / 14
1.0.913 14 / 14
1.0.912 14 / 14
1.0.911 14 / 14
1.0.910 14 / 14
1.0.909 14 / 14
1.0.908 14 / 14
1.0.907 14 / 14
1.0.906 14 / 14
1.0.905 14 / 14
1.0.904 14 / 14
1.0.903 14 / 14
1.0.902 14 / 14
1.0.901 14 / 14
1.0.900 14 / 14
1.0.899 14 / 14
1.0.898 14 / 14
1.0.897 14 / 14
Showing 100 of 1191 Next page →

v1.0.909

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.899

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.