← Home

@scrivr/export-pdf

PDF export for Scrivr documents — same layout pipeline as the canvas renderer

4
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

raphael-seraaai

Keywords

pdfexportcanvaseditorprosemirrorscrivr

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Package is a scoped workspace module in a monorepo; missing repo/keywords and inflated semver are consistent with internal tooling, not spam. ai
email-domain unclaimed-email:seraa.ai AI (email-domain): SLSA provenance attestation provides strong CI/CD identity assurance, partially offsetting the unclaimed domain risk for this package. ai

Versions (showing 4 of 4)

Version Deps Published
1.0.10 2 / 5
1.0.9 2 / 5
1.0.7 2 / 5
1.0.5 2 / 5

v1.0.10

2 findings
HIGH Unclaimed maintainer email domain: seraa.ai email-domain

Maintainer email '[email protected]' uses domain 'seraa.ai' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.9

2 findings
HIGH Unclaimed maintainer email domain: seraa.ai email-domain

Maintainer email '[email protected]' uses domain 'seraa.ai' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.7

2 findings
HIGH Unclaimed maintainer email domain: seraa.ai email-domain

Maintainer email '[email protected]' uses domain 'seraa.ai' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.