← Home

@nolebase/vitepress-plugin-enhanced-readabilities

5
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

nekomeowwwoikawa_rizumu

Keywords

vitepressnolebasea11yreadabilitiesmarkdownvitepress-pluginnolebase-integration

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:less AI (phantom-deps): less is a CSS preprocessor used in build config, not directly imported in source; stable false positive for this package. ai
phantom-deps phantom-dep:@iconify-json/carbon AI (phantom-deps): Icon JSON packages are referenced via config/plugin resolution, not direct imports; stable false positive. ai
phantom-deps phantom-dep:@iconify-json/icon-park-outline AI (phantom-deps): Icon JSON packages are referenced via config/plugin resolution, not direct imports; stable false positive. ai

Versions (showing 5 of 5)

Version Deps Published
2.18.2 4 / 1
2.18.1 4 / 1
2.18.0 4 / 1
2.17.2 4 / 1
2.17.1 4 / 1

v2.18.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.18.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.18.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.17.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.17.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.