@mintlify/previewing
Preview Mintlify docs locally
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@apidevtools/swagger-parser | AI (phantom-deps): Used for OpenAPI parsing, false-positive heuristic. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Standard remark plugin for docs rendering. | ai | |
| phantom-deps | phantom-dep:remark-mdx | AI (phantom-deps): Standard remark plugin for docs rendering. | ai | |
| phantom-deps | phantom-dep:gray-matter | AI (phantom-deps): Frontmatter parser, consistent with docs tooling. | ai | |
| phantom-deps | phantom-dep:remark-math | AI (phantom-deps): Standard remark plugin for docs rendering. | ai | |
| phantom-deps | phantom-dep:@octokit/rest | AI (phantom-deps): GitHub API client, plausible use in docs preview/publish flow. | ai | |
| phantom-deps | phantom-dep:is-absolute-url | AI (phantom-deps): Small utility, likely used but not import-detected. | ai | |
| phantom-deps | phantom-dep:remark-frontmatter | AI (phantom-deps): Standard remark plugin for docs rendering. | ai | |
| phantom-deps | phantom-dep:remark | AI (phantom-deps): Markdown processing dep used by docs preview tool; likely used indirectly via prebuild package. | ai | |
| dependencies | unvetted-dep:is-online | AI (dependencies): is-online is a well-known, widely-used npm package for network connectivity checks; appropriate for a local docs preview tool. Not a security risk. | ai | |
| phantom-deps | phantom-dep:front-matter | AI (phantom-deps): front-matter is declared as a dependency and used in the broader Mintlify ecosystem; phantom detection is a false positive for this package's usage pattern. | ai | |
| phantom-deps | phantom-dep:openapi-types | AI (phantom-deps): openapi-types is a type-only package; phantom detection is expected and not a security concern for this package. | ai | |
| phantom-deps | phantom-dep:unist-util-visit | AI (phantom-deps): unist-util-visit is used transitively in the Mintlify doc processing pipeline; phantom detection is a stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Package is published via GitHub Actions CI pipeline for a well-established org with 1161 versions and 132k weekly downloads. Lack of Sigstore provenance is acceptable here. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process (execFile) is used in export-scripts/serve.js for a local dev server — expected behavior for a docs previewing tool. Not a security risk. | ai |
Versions (showing 51 of 1252)
| Version | Deps | Published |
|---|---|---|
| 4.0.1263 | 21 / 18 | |
| 4.0.1262 | 21 / 18 | |
| 4.0.1261 | 21 / 18 | |
| 4.0.1260 | 21 / 18 | |
| 4.0.1259 | 21 / 18 | |
| 4.0.1258 | 21 / 18 | |
| 4.0.1257 | 21 / 18 | |
| 4.0.1256 | 21 / 18 | |
| 4.0.1255 | 21 / 18 | |
| 4.0.1254 | 21 / 18 | |
| 4.0.1253 | 21 / 18 | |
| 4.0.1252 | 21 / 18 | |
| 4.0.1251 | 21 / 18 | |
| 4.0.1250 | 21 / 18 | |
| 4.0.1249 | 21 / 18 | |
| 4.0.1248 | 21 / 18 | |
| 4.0.1247 | 21 / 18 | |
| 4.0.1246 | 21 / 18 | |
| 4.0.1245 | 21 / 18 | |
| 4.0.1244 | 21 / 18 | |
| 4.0.1243 | 21 / 18 | |
| 4.0.1242 | 21 / 18 | |
| 4.0.1241 | 21 / 18 | |
| 4.0.1240 | 21 / 18 | |
| 4.0.1239 | 21 / 18 | |
| 4.0.1238 | 21 / 18 | |
| 4.0.1237 | 21 / 18 | |
| 4.0.1236 | 21 / 18 | |
| 4.0.1235 | 21 / 18 | |
| 4.0.1234 | 21 / 18 | |
| 4.0.1233 | 21 / 18 | |
| 4.0.1232 | 21 / 18 | |
| 4.0.1231 | 21 / 18 | |
| 4.0.1230 | 21 / 18 | |
| 4.0.1229 | 21 / 18 | |
| 4.0.1228 | 21 / 18 | |
| 4.0.1227 | 21 / 18 | |
| 4.0.1226 | 21 / 18 | |
| 4.0.1225 | 21 / 18 | |
| 4.0.1224 | 21 / 18 | |
| 4.0.1223 | 21 / 18 | |
| 4.0.1222 | 21 / 18 | |
| 4.0.1221 | 21 / 18 | |
| 4.0.1220 | 21 / 18 | |
| 4.0.1219 | 21 / 18 | |
| 4.0.1218 | 21 / 18 | |
| 4.0.1217 | 21 / 18 | |
| 4.0.1216 | 21 / 18 | |
| 4.0.1215 | 21 / 18 | |
| 4.0.1213 | 21 / 18 | |
| 4.0.1212 | 21 / 18 |
v4.0.1263
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1262
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1261
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1260
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1259
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1258
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1257
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1256
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1255
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1254
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1253
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1252
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1251
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1250
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1249
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1248
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1247
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1246
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1245
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1244
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1243
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1242
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1241
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1240
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1239
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1238
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1237
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1236
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1235
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1234
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1233
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1232
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1231
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1230
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1229
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1228
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1227
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1226
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1225
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1224
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1223
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1222
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1221
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1220
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1219
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1218
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1217
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1216
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1215
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1213
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1212
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.