@seqera/docusaurus-preset-seqera
Docusaurus preset for Seqera docs
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:docusaurus-plugin-llms | AI (phantom-deps): Plugin referenced in preset config, not imported directly — expected pattern. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/oxide | AI (phantom-deps): CSS tooling dep used via config, not direct JS import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:docusaurus-theme-openapi-docs | AI (phantom-deps): Plugin/theme deps wired via Docusaurus config, not direct imports. | ai | |
| phantom-deps | phantom-dep:@docusaurus/core | AI (phantom-deps): Docusaurus preset; @docusaurus/core is a peer/config dep, not directly imported in JS. | ai | |
| phantom-deps | phantom-dep:docusaurus-theme-search-typesense | AI (phantom-deps): Plugin/theme deps wired via Docusaurus config, not direct imports. | ai | |
| phantom-deps | phantom-dep:@docusaurus/plugin-css-cascade-layers | AI (phantom-deps): Plugin dep wired via Docusaurus config, not direct imports. | ai | |
| phantom-deps | phantom-dep:docusaurus-plugin-openapi-docs | AI (phantom-deps): Plugin/theme deps wired via Docusaurus config, not direct imports. | ai | |
| dependencies | unvetted-dep:@docusaurus/theme-search-algolia | AI (dependencies): Official Docusaurus Algolia search theme. | ai | |
| dependencies | unvetted-dep:docusaurus-theme-search-typesense | AI (dependencies): Known Typesense search theme for Docusaurus. | ai | |
| dependencies | unvetted-dep:remark-code-import | AI (dependencies): Legitimate remark plugin; stable ecosystem package. | ai | |
| npm-metadata | url-dep:remark-yaml-to-table | AI (npm-metadata): Points to Seqera's own GitHub org; intentional for internal tooling. | ai | |
| dependencies | unvetted-dep:docusaurus-remark-plugin-tab-blocks | AI (dependencies): Known Docusaurus remark plugin; stable ecosystem package. | ai | |
| dependencies | unvetted-dep:remark-yaml-to-table | AI (dependencies): Seqera's own GitHub-hosted remark plugin; expected for internal tooling. | ai | |
| dependencies | unvetted-dep:docusaurus-plugin-llms | AI (dependencies): Known Docusaurus ecosystem plugin; no malware indicators. | ai | |
| dependencies | unvetted-dep:docusaurus-theme-openapi-docs | AI (dependencies): Known Docusaurus OpenAPI theme; stable ecosystem package. | ai | |
| dependencies | unvetted-dep:@docusaurus/plugin-google-gtag | AI (dependencies): Official Docusaurus plugin from the @docusaurus org. | ai | |
| dependencies | unvetted-dep:docusaurus-plugin-openapi-docs | AI (dependencies): Known Docusaurus OpenAPI plugin; stable ecosystem package. | ai | |
| dependencies | unvetted-dep:@seqera/docusaurus-theme-seqera | AI (dependencies): Seqera's own companion theme package; same publisher and version. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 1.0.38 | 25 / 0 | |
| 1.0.37 | 25 / 0 | |
| 1.0.35 | 25 / 0 | |
| 1.0.33 | 25 / 0 | |
| 1.0.32 | 25 / 0 | |
| 1.0.25 | 25 / 0 | |
| 1.0.24 | 25 / 0 | |
| 1.0.19 | 24 / 0 | |
| 1.0.18 | 24 / 0 | |
| 1.0.17 | 24 / 0 |
v1.0.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.