@redocly/redoc-reef
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed-stale | AI (provenance): CI-shaped publisher change (GitHub Actions), stable for this long-lived stayed-published version. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Publisher change stable/long-lived on npm, consistent with legitimate org transfer. | ai | |
| source-diff | bulk-obfuscated-files:dist | AI (source-diff): dist/ build output from esbuild-minify-dir, not obfuscation; sample shows i18n strings. | ai | |
| phantom-deps | phantom-dep:xpath | AI (phantom-deps): Minified build output; heuristic false positive for this bundled package. | ai | |
| phantom-deps | phantom-dep:anser | AI (phantom-deps): Minified build output; heuristic false positive for this bundled package. | ai | |
| phantom-deps | phantom-dep:ulid | AI (phantom-deps): Minified build output; heuristic false positive for this bundled package. | ai | |
| source-diff | obfuscated-file:dist/constants/l10n/langs/ar.js | AI (source-diff): Localization data file with unicode-escaped strings, not obfuscated code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected growth from new catalog-entities feature in official monorepo package. | ai | |
| source-diff | obfuscated-file:dist/server/plugins/catalog-entities/extensions/extractors/api-description/arazzo-entities-extractor.js | AI (source-diff): Bundled/minified esbuild output, readable logic, no malicious behavior. | ai | |
| phantom-deps | phantom-dep:@hono/zod-validator | AI (phantom-deps): New dep used by MCP tooling; config-only reference is a known pattern. | ai | |
| source-diff | obfuscated-file:dist/server/plugins/mcp/docs-mcp/tools/graphql/utils.js | AI (source-diff): Minified esbuild output per build:minify script, not true obfuscation. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api | AI (phantom-deps): OpenTelemetry packages loaded via config; stable pattern for this package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Monorepo package; missing description is common and low-risk. | ai | |
| phantom-deps | phantom-dep:babel-plugin-styled-components | AI (phantom-deps): Babel plugin loaded via config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped package loaded by convention in build pipeline. | ai | |
| phantom-deps | phantom-dep:@redocly/portal-plugin-mock-server | AI (phantom-deps): Same-org scoped package; likely loaded by convention. | ai | |
| dependencies | unvetted-dep:typesense | AI (dependencies): Known search client library; legitimate dep for a docs portal package. | ai | |
| dependencies | unvetted-dep:@wojtekmaj/react-datetimerange-picker | AI (dependencies): Known React date picker library; no malicious indicators. | ai | |
| dependencies | unvetted-dep:@redocly/portal-plugin-mock-server | AI (dependencies): Same org scope; legitimate internal dependency. | ai | |
| dependencies | unvetted-dep:@redocly/realm-asyncapi-sdk | AI (dependencies): Same org scope; legitimate internal dependency. | ai | |
| dependencies | unvetted-dep:@redocly/mcp-typescript-sdk | AI (dependencies): Same org scope; legitimate internal dependency. | ai | |
| dependencies | unvetted-dep:@opentelemetry/context-zone | AI (dependencies): Official OpenTelemetry package; well-known observability library. | ai | |
| dependencies | unvetted-dep:@redocly/portal-legacy-ui | AI (dependencies): Same org scope; legitimate internal dependency. | ai | |
| dependencies | unvetted-dep:@redocly/asyncapi-docs | AI (dependencies): Same org scope; legitimate internal dependency. | ai | |
| dependencies | unvetted-dep:@redocly/openapi-docs | AI (dependencies): Same org scope; legitimate internal dependency. | ai | |
| dependencies | unvetted-dep:@redocly/graphql-docs | AI (dependencies): Same org scope; legitimate internal dependency. | ai | |
| dependencies | unvetted-dep:yaml-ast-parser | AI (dependencies): Established YAML parsing library; expected in API docs tooling. | ai | |
| dependencies | unvetted-dep:@redocly/theme | AI (dependencies): Same org scope; legitimate internal dependency. | ai | |
| dependencies | unvetted-dep:flexsearch | AI (dependencies): Well-known search library; expected in a docs portal. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 0.135.0 | 87 / 0 | |
| 0.134.1 | 84 / 0 | |
| 0.134.0 | 85 / 0 | |
| 0.132.1 | 84 / 0 | |
| 0.132.0 | 84 / 0 | |
| 0.131.4 | 85 / 0 | |
| 0.131.3 | 85 / 0 | |
| 0.130.0 | 84 / 0 | |
| 0.129.1 | 87 / 0 | |
| 0.127.0 | 86 / 0 | |
| 0.123.1 | 83 / 0 | |
| 0.123.0 | 83 / 0 | |
| 0.122.2 | 82 / 0 | |
| 0.122.1 | 82 / 0 | |
| 0.122.0 | 82 / 0 | |
| 0.85.0 | 66 / 0 |
v0.135.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.134.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.130.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.129.1
2 findingsThis version was published by a different npm account (GitHub Actions) than the most recent previously approved version (volodymyr-rutskyi) on 2026-01-13. It has since remained available on npm for 189 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.127.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.122.0
2 findingsThis version was published by a different npm account (volodymyr-rutskyi) than the most recent previously approved version (marshevskyy) on 2025-06-10. It has since remained available on npm for 406 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.85.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.