@redocly/redoc
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/constants/l10n/langs/ar.js | AI (source-diff): Localization JSON strings escaped to \u, not code obfuscation. | ai | |
| source-diff | obfuscated-file:dist/server/constants/plugins/catalog-entities.js | AI (source-diff): Minified constants file, plain config object. | ai | |
| source-diff | obfuscated-file:dist/server/plugins/catalog-entities/database/catalog-entities-service.js | AI (source-diff): Minified service glue code, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/server/plugins/catalog-entities/database/repositories/remote/catalog-entities-remote-repository.js | AI (source-diff): Minified DB repository code; env vars used for user-configured sync DB, not exfil. | ai | |
| source-diff | obfuscated-file:dist/server/plugins/catalog-entities/database/repositories/local/catalog-entities-local-read-repository.js | AI (source-diff): Minified drizzle-orm DB repository code, legitimate feature code. | ai | |
| source-diff | obfuscated-file:dist/server/plugins/catalog-entities/extensions/extractors/api-description/asyncapi-entities-extractor.js | AI (source-diff): esbuild-minified build output; no malicious behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/server/plugins/catalog-entities/extensions/extractors/api-description/arazzo-entities-extractor.js | AI (source-diff): esbuild-minified build output per package.json build:minify script. | ai | |
| source-diff | obfuscated-file:dist/server/persistence/kv/repositories/kv-repository.js | AI (source-diff): Minified build output, no malicious behavior present. | ai | |
| source-diff | obfuscated-file:dist/server/web-server/routes/mcp-routes/mcp-oauth.js | AI (source-diff): Minified OAuth route code, standard bundler output. | ai | |
| source-diff | obfuscated-file:dist/server/plugins/catalog-entities/database/catalog-entities-publisher.js | AI (source-diff): Minified build output from legit monorepo, not injected obfuscation. | ai | |
| dependencies | unvetted-dep:yaml-ast-parser | AI (dependencies): Long-standing legitimate YAML parsing dep for OpenAPI tooling. | ai | |
| phantom-deps | phantom-dep:openapi-sampler | AI (phantom-deps): Used indirectly via build config, not a direct import. | ai | |
| phantom-deps | phantom-dep:xpath | AI (phantom-deps): Large monorepo config-referenced dep, stable false positive. | ai | |
| source-diff | obfuscated-file:dist/server/plugins/mcp/docs-mcp/tools/graphql/utils.js | AI (source-diff): Minified esbuild bundler output, not true obfuscation; no malicious behavior present. | ai | |
| dependencies | unvetted-dep:@redocly/mcp-typescript-sdk | AI (dependencies): First-party Redocly-scoped package | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Monorepo config-referenced dep, stable FP pattern for this package. | ai | |
| phantom-deps | phantom-dep:anser | AI (phantom-deps): Monorepo config-referenced dep, stable FP pattern for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Spam heuristics don't apply to this long-established, widely-used package. | ai | |
| phantom-deps | phantom-dep:ulid | AI (phantom-deps): Large monorepo package; config-referenced deps are expected false positives. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Cosmetic metadata gap on an established, trusted package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large first-party server codebase (catalog/MCP); expected growth for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @emotion/is-prop-valid is standard styled-components helper; benign. | ai | |
| typosquat | typosquat.levenshtein:redis | AI (typosquat): @redocly/redoc is a well-known scoped package from the Redocly org; not a typosquat of redis. | ai | |
| phantom-deps | phantom-dep:@redocly/portal-plugin-mock-server | AI (phantom-deps): Same-org plugin dependency; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a peer dependency declared in peerDependencies; phantom-dep heuristic false positive. | ai | |
| typosquat | typosquat.levenshtein:redux | AI (typosquat): @redocly/redoc is a well-known scoped package from the Redocly org; not a typosquat of redux. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 0.135.0 | 87 / 0 | |
| 0.134.0 | 85 / 0 | |
| 0.133.1 | 84 / 0 | |
| 0.132.1 | 84 / 0 | |
| 0.131.3 | 85 / 0 | |
| 0.131.1 | 85 / 0 | |
| 0.130.4 | 84 / 0 | |
| 0.130.3 | 84 / 0 | |
| 0.130.0 | 84 / 0 | |
| 0.129.2 | 87 / 0 | |
| 0.128.1 | 86 / 0 | |
| 0.128.0 | 86 / 0 | |
| 0.127.0 | 86 / 0 | |
| 0.123.0 | 83 / 0 | |
| 0.122.3 | 82 / 0 | |
| 0.122.2 | 82 / 0 | |
| 0.122.0 | 82 / 0 | |
| 0.121.1 | 80 / 0 | |
| 0.85.0 | 66 / 0 |
v0.135.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.134.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.133.1
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.131.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.130.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.130.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.130.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.129.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.128.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.128.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.127.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.123.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.122.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.122.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.122.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.121.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.85.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.