← Home

@mrts/mdkit

MRTS - mdkit

24
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

microu

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:unist AI (dependencies): [email protected] is a known stub package in the unified/remark ecosystem; low risk. ai
phantom-deps phantom-dep:unist AI (phantom-deps): unist is a type-stub package used as a peer/type dep in the remark ecosystem; not directly imported is expected. ai
provenance no-provenance AI (provenance): Small markdown toolkit; no provenance is common and not a disqualifier here. ai
dependencies unvetted-dep:@types/hast AI (dependencies): Standard DefinitelyTyped type package for the hast AST; no risk. ai
dependencies unvetted-dep:@types/yaml AI (dependencies): Standard DefinitelyTyped type package; no risk. ai
dependencies unvetted-dep:@types/mdast AI (dependencies): Standard DefinitelyTyped type package for mdast AST; no risk. ai
dependencies unvetted-dep:mdast-builder AI (dependencies): Well-known mdast utility in the unified ecosystem; no risk. ai
dependencies unvetted-dep:mdast-util-to-string AI (dependencies): Well-known mdast utility in the unified ecosystem; no risk. ai
dependencies unvetted-dep:@mrts/common AI (dependencies): Same org scope as this package; expected internal dependency. ai
dependencies unvetted-dep:@mrts/common-node AI (dependencies): Same org scope as this package; expected internal dependency. ai
phantom-deps phantom-dep:@types/hast AI (phantom-deps): @types/* packages are type-only and loaded by convention; not directly imported in JS. ai
phantom-deps phantom-dep:@types/unist AI (phantom-deps): @types/* packages are type-only and loaded by convention; not directly imported in JS. ai
phantom-deps phantom-dep:@types/mdast AI (phantom-deps): @types/* packages are type-only and loaded by convention; not directly imported in JS. ai
phantom-deps phantom-dep:@types/yaml AI (phantom-deps): @types/* packages are type-only and loaded by convention; not directly imported in JS. ai
phantom-deps phantom-dep:@mrts/common AI (phantom-deps): Same org scope; likely used transitively or via re-exports. ai
phantom-deps phantom-dep:@mrts/common-node AI (phantom-deps): Same org scope; likely used transitively or via re-exports. ai
phantom-deps phantom-dep:vfile AI (phantom-deps): Referenced in config; standard unified ecosystem dependency. ai
phantom-deps phantom-dep:mdast-builder AI (phantom-deps): Referenced in config; standard mdast ecosystem dependency. ai
phantom-deps phantom-dep:mdast-util-to-hast AI (phantom-deps): Referenced in config; standard mdast/hast ecosystem dependency. ai
phantom-deps phantom-dep:hast-util-to-string AI (phantom-deps): Referenced in config; standard hast ecosystem dependency. ai

Versions (showing 24 of 24)

Version Deps Published
0.5.10 23 / 4
0.5.7 23 / 3
0.5.6 23 / 3
0.5.5 21 / 3
0.5.4 21 / 3
0.5.3 18 / 4
0.5.2 18 / 4
0.5.1 18 / 4
0.5.0 13 / 9
0.4.99 13 / 9
0.4.35 13 / 9
0.4.18 16 / 6
0.4.3 13 / 6
0.4.1 5 / 3
0.4.0 5 / 3
0.3.5 5 / 3
0.3.4 5 / 3
0.3.0 5 / 3
0.2.10 5 / 3
0.2.9 5 / 3
0.2.7 5 / 3
0.2.6 5 / 3
0.2.1 5 / 3
0.2.0 5 / 3

v0.5.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.99

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.35

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.