@readme/markdown
ReadMe's React-based Markdown parser
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:estree-util-build-jsx | AI (phantom-deps): Bundled dep; phantom-dep is a false positive for this webpack-bundled package. | ai | |
| phantom-deps | phantom-dep:mdast-util-mdxjs-esm | AI (phantom-deps): Bundled dep; phantom-dep is a false positive for this webpack-bundled package. | ai | |
| phantom-deps | phantom-dep:micromark-extension-mdxjs-esm | AI (phantom-deps): Bundled dep; phantom-dep is a false positive for this webpack-bundled package. | ai | |
| source-diff | encoded-string-file:dist/main.js | AI (source-diff): Encoded string is htmlparser2/entities decode trie (base64-packed HTML entity data), not obfuscated malware. | ai | |
| source-diff | encoded-string-file:dist/main.node.js | AI (source-diff): Same htmlparser2/entities decode trie pattern in node bundle; benign data encoding. | ai | |
| phantom-deps | phantom-dep:htmlparser2 | AI (phantom-deps): Bundled into dist via webpack; not directly imported in source but legitimately used. | ai | |
| phantom-deps | phantom-dep:estree-util-to-js | AI (phantom-deps): Bundled dep; phantom-dep is a false positive for this webpack-bundled package. | ai | |
| phantom-deps | phantom-dep:micromark-extension-mdxjs | AI (phantom-deps): Config-driven plugin loading; stable pattern for this markdown processor. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are legitimate unified/micromark ecosystem packages matching the package's MDX parsing purpose. | ai | |
| dependencies | unvetted-dep:rehype-react | AI (dependencies): Well-known unified/rehype ecosystem package; stable dependency for this markdown parser. | ai | |
| dependencies | unvetted-dep:@readme/syntax-highlighter | AI (dependencies): Same org (@readme) as this package; expected internal dependency. | ai | |
| dependencies | unvetted-dep:@readme/emojis | AI (dependencies): Same org (@readme) as this package; expected internal dependency. | ai | |
| dependencies | unvetted-dep:@readme/variable | AI (dependencies): Same org (@readme) as this package; expected internal dependency. | ai | |
| dependencies | unvetted-dep:xast-util-to-xml | AI (dependencies): Well-known unified ecosystem utility; stable dependency for this markdown parser. | ai | |
| dependencies | unvetted-dep:unist-util-flatmap | AI (dependencies): Well-known unified ecosystem utility; stable dependency for this markdown parser. | ai | |
| dependencies | unvetted-dep:react-native-known-styling-properties | AI (dependencies): Used for CSS property validation in the markdown renderer; benign data package. | ai | |
| phantom-deps | phantom-dep:postcss-prefix-selector | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:react-html-attributes | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:micromark-util-symbol | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:mdast-util-phrasing | AI (phantom-deps): Stable false positive; bundled package with many transitive deps not directly imported at top level. | ai | |
| phantom-deps | phantom-dep:hast-util-from-html | AI (phantom-deps): Declared in package.json as a runtime dep; phantom-dep heuristic false positive for this bundled package. | ai | |
| phantom-deps | phantom-dep:estree-util-value-to-estree | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:mdast-util-mdx-expression | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:unist-util-visit-parents | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:mdast-util-find-and-replace | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:mdast-util-gfm-strikethrough | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:micromark-util-html-tag-name | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:micromark-extension-mdx-expression | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:micromark-extension-gfm-strikethrough | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:micromark-util-character | AI (phantom-deps): Stable false positive for this bundled markdown package. | ai | |
| phantom-deps | phantom-dep:hast-util-sanitize | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:html-tags | AI (phantom-deps): Large bundled markdown package; many deps used indirectly via webpack bundle, not direct imports. | ai | |
| phantom-deps | phantom-dep:hastscript | AI (phantom-deps): Same as above — bundled dependency pattern for this package. | ai | |
| phantom-deps | phantom-dep:rehype-raw | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:remark-mdx | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:rehype-parse | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:remark-parse | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:lodash.escape | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:rehype-remark | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:remark-breaks | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:remark-rehype | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:github-slugger | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:mdast-util-gfm | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:path-browserify | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:rehype-sanitize | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:lodash.kebabcase | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:rehype-stringify | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:remark-stringify | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:unist-util-visit | AI (phantom-deps): Bundled dependency pattern. | ai | |
| phantom-deps | phantom-dep:debug | AI (phantom-deps): Large bundled package; deps consumed transitively or via config, not direct imports. | ai | |
| phantom-deps | phantom-dep:react-native-known-styling-properties | AI (phantom-deps): Platform-specific dep used in bundle; stable false positive. | ai | |
| phantom-deps | phantom-dep:unist-util-flatmap | AI (phantom-deps): Transitive/bundled dep pattern for this package. | ai | |
| phantom-deps | phantom-dep:xast-util-to-xml | AI (phantom-deps): Transitive/bundled dep pattern for this package. | ai | |
| phantom-deps | phantom-dep:@readme/variable | AI (phantom-deps): Same-org dep; consumed via bundle, stable false positive. | ai | |
| phantom-deps | phantom-dep:@readme/emojis | AI (phantom-deps): Same-org dep; consumed via bundle, stable false positive. | ai | |
| phantom-deps | phantom-dep:rehype-react | AI (phantom-deps): Transitive/bundled dep pattern for this package. | ai | |
| phantom-deps | phantom-dep:deepmerge | AI (phantom-deps): Transitive/bundled dep pattern for this package. | ai | |
| phantom-deps | phantom-dep:entities | AI (phantom-deps): Transitive/bundled dep pattern for this package. | ai | |
| phantom-deps | phantom-dep:process | AI (phantom-deps): Webpack polyfill; referenced in webpack config, not direct import. | ai | |
| phantom-deps | phantom-dep:remark | AI (phantom-deps): Same as above — bundled markdown library pattern. | ai |
Versions (showing 84 of 84)
| Version | Deps | Published |
|---|---|---|
| 14.10.1 | 64 / 64 | |
| 14.10.0 | 64 / 64 | |
| 14.9.0 | 64 / 64 | |
| 14.8.1 | 64 / 64 | |
| 14.8.0 | 64 / 64 | |
| 14.7.2 | 64 / 64 | |
| 14.7.1 | 64 / 64 | |
| 14.7.0 | 64 / 64 | |
| 14.6.0 | 64 / 64 | |
| 14.5.0 | 64 / 64 | |
| 14.4.1 | 64 / 64 | |
| 14.4.0 | 64 / 64 | |
| 14.3.0 | 64 / 64 | |
| 14.2.6 | 60 / 64 | |
| 14.2.5 | 60 / 64 | |
| 14.2.4 | 59 / 64 | |
| 14.2.3 | 59 / 64 | |
| 14.2.2 | 59 / 64 | |
| 14.2.1 | 59 / 64 | |
| 14.2.0 | 57 / 64 | |
| 14.1.4 | 57 / 64 | |
| 14.1.3 | 57 / 64 | |
| 14.1.2 | 57 / 64 | |
| 14.1.1 | 57 / 64 | |
| 14.1.0 | 57 / 64 | |
| 14.0.0 | 57 / 64 | |
| 13.8.5 | 57 / 64 | |
| 13.8.4 | 57 / 64 | |
| 13.8.3 | 57 / 64 | |
| 13.8.2 | 57 / 64 | |
| 13.8.1 | 57 / 64 | |
| 13.8.0 | 57 / 64 | |
| 13.7.4 | 57 / 64 | |
| 13.7.3 | 57 / 64 | |
| 13.7.2 | 57 / 64 | |
| 13.7.1 | 57 / 64 | |
| 13.7.0 | 57 / 64 | |
| 13.6.3 | 57 / 64 | |
| 13.6.2 | 56 / 64 | |
| 13.6.1 | 56 / 64 | |
| 13.6.0 | 56 / 64 | |
| 13.5.0 | 56 / 64 | |
| 13.4.0 | 53 / 64 | |
| 13.3.0 | 53 / 64 | |
| 13.2.0 | 52 / 64 | |
| 13.1.4 | 52 / 64 | |
| 13.1.3 | 52 / 64 | |
| 13.1.2 | 52 / 64 | |
| 13.1.1 | 48 / 64 | |
| 13.1.0 | 48 / 64 | |
| 13.0.0 | 48 / 64 | |
| 12.2.0 | 46 / 64 | |
| 12.1.1 | 46 / 64 | |
| 12.1.0 | 46 / 64 | |
| 12.0.1 | 46 / 64 | |
| 12.0.0 | 46 / 64 | |
| 11.15.0 | 46 / 64 | |
| 11.14.1 | 46 / 64 | |
| 11.14.0 | 46 / 64 | |
| 11.13.0 | 46 / 64 | |
| 11.12.1 | 46 / 64 | |
| 11.12.0 | 46 / 64 | |
| 11.11.0 | 46 / 64 | |
| 11.10.1 | 46 / 64 | |
| 11.10.0 | 46 / 64 | |
| 11.9.4 | 46 / 64 | |
| 11.9.3 | 46 / 64 | |
| 11.9.2 | 46 / 64 | |
| 11.9.1 | 46 / 64 | |
| 11.9.0 | 46 / 64 | |
| 11.8.2 | 46 / 64 | |
| 11.8.1 | 46 / 64 | |
| 11.8.0 | 46 / 64 | |
| 11.7.7 | 39 / 64 | |
| 11.7.6 | 39 / 64 | |
| 11.7.5 | 39 / 64 | |
| 11.7.4 | 39 / 64 | |
| 11.7.3 | 39 / 64 | |
| 11.7.2 | 39 / 64 | |
| 11.7.1 | 39 / 64 | |
| 11.7.0 | 39 / 64 | |
| 11.6.0 | 39 / 64 | |
| 11.5.2 | 39 / 64 | |
| 11.5.1 | 39 / 64 |
v14.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.7.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.6.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.6.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v12.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.15.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.14.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.14.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.12.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.9.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.9.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.9.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.9.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.9.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (rafegoldberg) on 2025-12-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v11.8.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.8.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.7.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.7.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.7.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.7.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.7.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.7.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.5.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v11.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.