← Home

@mrts/mdkit

MRTS - mdkit

6
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

microu

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Small markdown toolkit; no provenance is common and not a disqualifier here. ai
dependencies unvetted-dep:@types/yaml AI (dependencies): Standard DefinitelyTyped type package; no risk. ai
dependencies unvetted-dep:@types/mdast AI (dependencies): Standard DefinitelyTyped type package for mdast AST; no risk. ai
dependencies unvetted-dep:mdast-builder AI (dependencies): Well-known mdast utility in the unified ecosystem; no risk. ai
dependencies unvetted-dep:@types/hast AI (dependencies): Standard DefinitelyTyped type package for the hast AST; no risk. ai
dependencies unvetted-dep:@mrts/common AI (dependencies): Same org scope as this package; expected internal dependency. ai
dependencies unvetted-dep:@mrts/common-node AI (dependencies): Same org scope as this package; expected internal dependency. ai
dependencies unvetted-dep:mdast-util-to-string AI (dependencies): Well-known mdast utility in the unified ecosystem; no risk. ai
phantom-deps phantom-dep:mdast-util-to-hast AI (phantom-deps): Referenced in config; standard mdast/hast ecosystem dependency. ai
phantom-deps phantom-dep:@types/hast AI (phantom-deps): @types/* packages are type-only and loaded by convention; not directly imported in JS. ai
phantom-deps phantom-dep:hast-util-to-string AI (phantom-deps): Referenced in config; standard hast ecosystem dependency. ai
phantom-deps phantom-dep:@types/yaml AI (phantom-deps): @types/* packages are type-only and loaded by convention; not directly imported in JS. ai
phantom-deps phantom-dep:@types/mdast AI (phantom-deps): @types/* packages are type-only and loaded by convention; not directly imported in JS. ai
phantom-deps phantom-dep:@types/unist AI (phantom-deps): @types/* packages are type-only and loaded by convention; not directly imported in JS. ai
phantom-deps phantom-dep:@mrts/common AI (phantom-deps): Same org scope; likely used transitively or via re-exports. ai
phantom-deps phantom-dep:@mrts/common-node AI (phantom-deps): Same org scope; likely used transitively or via re-exports. ai
phantom-deps phantom-dep:vfile AI (phantom-deps): Referenced in config; standard unified ecosystem dependency. ai
phantom-deps phantom-dep:mdast-builder AI (phantom-deps): Referenced in config; standard mdast ecosystem dependency. ai

Versions (showing 6 of 6)

Version Deps Published
0.5.7 23 / 3
0.5.6 23 / 3
0.5.5 21 / 3
0.5.4 21 / 3
0.3.4 5 / 3
0.3.0 5 / 3

v0.5.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.