← Home

@seqera/docusaurus-preset-seqera

Docusaurus preset for Seqera docs

10
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

vishal_seqerachrishakkseqera-sa-engewelsdana-seqera

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:docusaurus-plugin-llms AI (phantom-deps): Plugin referenced in preset config, not imported directly — expected pattern. ai
phantom-deps phantom-dep:@tailwindcss/oxide AI (phantom-deps): CSS tooling dep used via config, not direct JS import; stable false positive for this package. ai
phantom-deps phantom-dep:docusaurus-theme-openapi-docs AI (phantom-deps): Plugin/theme deps wired via Docusaurus config, not direct imports. ai
phantom-deps phantom-dep:@docusaurus/core AI (phantom-deps): Docusaurus preset; @docusaurus/core is a peer/config dep, not directly imported in JS. ai
phantom-deps phantom-dep:docusaurus-theme-search-typesense AI (phantom-deps): Plugin/theme deps wired via Docusaurus config, not direct imports. ai
phantom-deps phantom-dep:@docusaurus/plugin-css-cascade-layers AI (phantom-deps): Plugin dep wired via Docusaurus config, not direct imports. ai
phantom-deps phantom-dep:docusaurus-plugin-openapi-docs AI (phantom-deps): Plugin/theme deps wired via Docusaurus config, not direct imports. ai
dependencies unvetted-dep:@docusaurus/theme-search-algolia AI (dependencies): Official Docusaurus Algolia search theme. ai
dependencies unvetted-dep:docusaurus-theme-search-typesense AI (dependencies): Known Typesense search theme for Docusaurus. ai
dependencies unvetted-dep:remark-code-import AI (dependencies): Legitimate remark plugin; stable ecosystem package. ai
npm-metadata url-dep:remark-yaml-to-table AI (npm-metadata): Points to Seqera's own GitHub org; intentional for internal tooling. ai
dependencies unvetted-dep:docusaurus-remark-plugin-tab-blocks AI (dependencies): Known Docusaurus remark plugin; stable ecosystem package. ai
dependencies unvetted-dep:remark-yaml-to-table AI (dependencies): Seqera's own GitHub-hosted remark plugin; expected for internal tooling. ai
dependencies unvetted-dep:docusaurus-plugin-llms AI (dependencies): Known Docusaurus ecosystem plugin; no malware indicators. ai
dependencies unvetted-dep:docusaurus-theme-openapi-docs AI (dependencies): Known Docusaurus OpenAPI theme; stable ecosystem package. ai
dependencies unvetted-dep:@docusaurus/plugin-google-gtag AI (dependencies): Official Docusaurus plugin from the @docusaurus org. ai
dependencies unvetted-dep:docusaurus-plugin-openapi-docs AI (dependencies): Known Docusaurus OpenAPI plugin; stable ecosystem package. ai
dependencies unvetted-dep:@seqera/docusaurus-theme-seqera AI (dependencies): Seqera's own companion theme package; same publisher and version. ai

Versions (showing 10 of 10)

Version Deps Published
1.0.38 25 / 0
1.0.37 25 / 0
1.0.35 25 / 0
1.0.33 25 / 0
1.0.32 25 / 0
1.0.25 25 / 0
1.0.24 25 / 0
1.0.19 24 / 0
1.0.18 24 / 0
1.0.17 24 / 0

v1.0.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.