@patternfly/documentation-framework
A framework to build documentation for PatternFly.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:responsive-loader | AI (dependencies): Webpack image loader; expected in a documentation build framework. | ai | |
| provenance | publisher-changed | AI (provenance): kmcfaul is a PatternFly/Red Hat contributor; publisher transition is consistent with org maintainer rotation. | ai | |
| phantom-deps | phantom-dep:webpack-cli | AI (phantom-deps): webpack-cli is declared as a dependency and used in build scripts; phantom-dep heuristic false positive. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): Pinned templating dep in a doc framework; expected usage pattern. | ai | |
| dependencies | unvetted-dep:@patternfly/ast-helpers | AI (dependencies): First-party PatternFly scoped package; stable for this package. | ai | |
| dependencies | unvetted-dep:html-formatter | AI (dependencies): Pinned utility dep in a doc framework; expected usage pattern. | ai | |
| dependencies | unvetted-dep:hast-to-hyperscript | AI (dependencies): Pinned AST utility dep; standard in MDX/remark doc toolchains. | ai | |
| phantom-deps | phantom-dep:puppeteer | AI (phantom-deps): Used indirectly via puppeteer-cluster for screenshot generation; stable false positive. | ai | |
| phantom-deps | phantom-dep:css-loader | AI (phantom-deps): Webpack loader referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:file-saver | AI (phantom-deps): Referenced in config/build context; stable false positive. | ai | |
| phantom-deps | phantom-dep:url-loader | AI (phantom-deps): Webpack loader in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped, loaded by convention via babel-loader; stable false positive. | ai | |
| phantom-deps | phantom-dep:postcss-loader | AI (phantom-deps): Webpack loader in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:null-loader | AI (phantom-deps): Webpack loader in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:babel-loader | AI (phantom-deps): Webpack loader in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/preset-env | AI (phantom-deps): Framework-scoped babel preset; stable false positive. | ai | |
| phantom-deps | phantom-dep:webpack-dev-server | AI (phantom-deps): Dev server referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/preset-react | AI (phantom-deps): Framework-scoped babel preset; stable false positive. | ai | |
| phantom-deps | phantom-dep:file-loader | AI (phantom-deps): Webpack loader in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:html-formatter | AI (phantom-deps): Referenced in config context; stable false positive. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Used for live component preview rendering in a docs framework — expected pattern, not malicious. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads user-configured route files by convention; standard docs framework pattern. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): CLI build tool uses fork() to spawn build processes; expected for a build/docs framework. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): Webpack/build config-injected loader; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:process | AI (phantom-deps): Browser polyfill referenced in webpack config; stable false positive. | ai |
Versions (showing 100 of 275)
| Version | Deps | Published |
|---|---|---|
| 6.49.4 | 58 / 0 | |
| 6.49.3 | 58 / 0 | |
| 6.49.2 | 58 / 0 | |
| 6.49.1 | 58 / 0 | |
| 6.49.0 | 58 / 0 | |
| 6.48.1 | 58 / 0 | |
| 6.48.0 | 58 / 0 | |
| 6.47.0 | 58 / 0 | |
| 6.46.1 | 58 / 0 | |
| 6.46.0 | 58 / 0 | |
| 6.45.0 | 58 / 0 | |
| 6.44.5 | 58 / 0 | |
| 6.44.4 | 58 / 0 | |
| 6.44.3 | 58 / 0 | |
| 6.44.2 | 58 / 0 | |
| 6.44.1 | 58 / 0 | |
| 6.44.0 | 58 / 0 | |
| 6.43.7 | 58 / 0 | |
| 6.43.6 | 58 / 0 | |
| 6.43.5 | 58 / 0 | |
| 6.43.0 | 58 / 0 | |
| 6.42.2 | 58 / 0 | |
| 6.42.1 | 58 / 0 | |
| 6.42.0 | 58 / 0 | |
| 6.41.0 | 58 / 0 | |
| 6.40.4 | 58 / 0 | |
| 6.40.3 | 58 / 0 | |
| 6.40.2 | 58 / 0 | |
| 6.40.1 | 58 / 0 | |
| 6.40.0 | 58 / 0 | |
| 6.39.2 | 58 / 0 | |
| 6.39.1 | 58 / 0 | |
| 6.39.0 | 58 / 0 | |
| 6.38.7 | 58 / 0 | |
| 6.38.6 | 58 / 0 | |
| 6.38.5 | 58 / 0 | |
| 6.38.4 | 58 / 0 | |
| 6.38.3 | 58 / 0 | |
| 6.38.2 | 58 / 0 | |
| 6.38.1 | 58 / 0 | |
| 6.38.0 | 58 / 0 | |
| 6.37.0 | 58 / 0 | |
| 6.36.8 | 58 / 0 | |
| 6.36.7 | 58 / 0 | |
| 6.36.6 | 58 / 0 | |
| 6.36.5 | 58 / 0 | |
| 6.36.4 | 58 / 0 | |
| 6.36.3 | 58 / 0 | |
| 6.36.2 | 58 / 0 | |
| 6.36.1 | 58 / 0 | |
| 6.36.0 | 58 / 0 | |
| 6.35.1 | 58 / 0 | |
| 6.35.0 | 58 / 0 | |
| 6.34.1 | 58 / 0 | |
| 6.34.0 | 58 / 0 | |
| 6.33.11 | 58 / 0 | |
| 6.33.10 | 58 / 0 | |
| 6.33.9 | 58 / 0 | |
| 6.33.8 | 56 / 0 | |
| 6.33.7 | 56 / 0 | |
| 6.33.6 | 56 / 0 | |
| 6.33.5 | 56 / 0 | |
| 6.33.4 | 56 / 0 | |
| 6.33.3 | 56 / 0 | |
| 6.33.2 | 56 / 0 | |
| 6.33.1 | 56 / 0 | |
| 6.33.0 | 56 / 0 | |
| 6.32.0 | 56 / 0 | |
| 6.31.15 | 56 / 0 | |
| 6.31.14 | 56 / 0 | |
| 6.31.13 | 56 / 0 | |
| 6.31.12 | 56 / 0 | |
| 6.31.11 | 56 / 0 | |
| 6.31.10 | 56 / 0 | |
| 6.31.9 | 56 / 0 | |
| 6.31.8 | 56 / 0 | |
| 6.31.7 | 56 / 0 | |
| 6.31.6 | 56 / 0 | |
| 6.31.5 | 56 / 0 | |
| 6.31.4 | 56 / 0 | |
| 6.31.3 | 56 / 0 | |
| 6.31.2 | 56 / 0 | |
| 6.31.1 | 56 / 0 | |
| 6.31.0 | 56 / 0 | |
| 6.30.1 | 56 / 0 | |
| 6.30.0 | 56 / 0 | |
| 6.29.1 | 56 / 0 | |
| 6.29.0 | 56 / 0 | |
| 6.28.10 | 61 / 0 | |
| 6.28.9 | 61 / 0 | |
| 6.28.8 | 62 / 0 | |
| 6.28.7 | 62 / 0 | |
| 6.28.6 | 62 / 0 | |
| 6.28.5 | 62 / 0 | |
| 6.28.4 | 62 / 0 | |
| 6.28.3 | 62 / 0 | |
| 6.28.2 | 62 / 0 | |
| 6.28.1 | 62 / 0 | |
| 6.28.0 | 62 / 0 | |
| 6.27.3 | 62 / 0 |
v6.49.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.49.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.49.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.49.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.49.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.48.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.48.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.47.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.46.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.46.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.45.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.44.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.44.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.44.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2026-06-15. This could indicate a legitimate maintainer transition or an account compromise.
v6.44.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ausuliv) than the most recent previously approved version (dlabaj) on 2026-06-04, but ausuliv is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.44.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ausuliv) than the most recent previously approved version (dlabaj) on 2026-05-26, but ausuliv is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.43.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.43.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.43.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (dlabaj) than the most recent previously approved version (ausuliv) on 2026-05-21, but dlabaj is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.43.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.42.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.42.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.42.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.41.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.40.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.40.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.40.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.40.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.39.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.39.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.38.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.38.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.38.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.38.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.38.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.38.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.36.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.36.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.36.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.36.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.36.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.36.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.36.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.36.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.35.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.35.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.34.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.33.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.32.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.30.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.30.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.29.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.29.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.28.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.28.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.28.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ausuliv) than the most recent previously approved version (patternfly-build) on 2025-10-22, but ausuliv is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.28.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ausuliv) than the most recent previously approved version (patternfly-build) on 2025-10-21, but ausuliv is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v6.28.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.28.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.28.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.28.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.28.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.28.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.27.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.