@thi.ng/hiccup-markdown
Markdown parser & serializer from/to Hiccup format
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@thi.ng/api | AI (dependencies): Same thi.ng umbrella monorepo; stable sibling dependency. | ai | |
| dependencies | unvetted-dep:@thi.ng/parse | AI (dependencies): Same thi.ng umbrella monorepo; stable sibling dependency. | ai | |
| dependencies | unvetted-dep:@thi.ng/arrays | AI (dependencies): Same thi.ng umbrella monorepo; stable sibling dependency. | ai | |
| dependencies | unvetted-dep:@thi.ng/hiccup | AI (dependencies): Same thi.ng umbrella monorepo; stable sibling dependency. | ai | |
| dependencies | unvetted-dep:@thi.ng/strings | AI (dependencies): Same thi.ng umbrella monorepo; stable sibling dependency. | ai | |
| dependencies | unvetted-dep:@thi.ng/defmulti | AI (dependencies): Same thi.ng umbrella monorepo; stable sibling dependency. | ai | |
| dependencies | unvetted-dep:@thi.ng/text-canvas | AI (dependencies): Same thi.ng umbrella monorepo; stable sibling dependency. | ai | |
| provenance | no-provenance | AI (provenance): thi.ng umbrella does not use Sigstore provenance; consistent across all versions. | ai |
Versions (showing 51 of 56)
| Version | Deps | Published |
|---|---|---|
| 3.2.198 | 11 / 3 | |
| 3.2.197 | 11 / 3 | |
| 3.2.196 | 11 / 3 | |
| 3.2.194 | 11 / 3 | |
| 3.2.193 | 11 / 3 | |
| 3.2.191 | 11 / 3 | |
| 3.2.190 | 11 / 3 | |
| 3.2.189 | 11 / 3 | |
| 3.2.188 | 11 / 3 | |
| 3.2.187 | 11 / 3 | |
| 3.2.186 | 11 / 3 | |
| 3.2.185 | 11 / 3 | |
| 3.2.184 | 11 / 3 | |
| 3.2.183 | 11 / 3 | |
| 3.2.182 | 11 / 3 | |
| 3.2.181 | 11 / 3 | |
| 3.2.180 | 11 / 3 | |
| 3.2.178 | 11 / 3 | |
| 3.2.177 | 11 / 3 | |
| 3.2.176 | 11 / 3 | |
| 3.2.175 | 11 / 3 | |
| 3.2.174 | 11 / 3 | |
| 3.2.173 | 11 / 3 | |
| 3.2.172 | 11 / 3 | |
| 3.2.171 | 11 / 3 | |
| 3.2.170 | 11 / 3 | |
| 3.2.169 | 11 / 3 | |
| 3.2.168 | 11 / 3 | |
| 3.2.167 | 11 / 3 | |
| 3.2.163 | 11 / 3 | |
| 3.2.162 | 11 / 3 | |
| 3.2.161 | 11 / 3 | |
| 3.2.160 | 11 / 3 | |
| 3.2.159 | 11 / 3 | |
| 3.2.158 | 11 / 3 | |
| 3.2.157 | 11 / 3 | |
| 3.2.155 | 11 / 3 | |
| 3.2.154 | 11 / 3 | |
| 3.2.153 | 11 / 3 | |
| 3.2.152 | 11 / 3 | |
| 3.2.151 | 11 / 3 | |
| 3.2.149 | 11 / 3 | |
| 3.2.148 | 11 / 3 | |
| 3.2.147 | 11 / 3 | |
| 3.2.146 | 11 / 3 | |
| 3.2.145 | 11 / 3 | |
| 3.2.144 | 11 / 3 | |
| 3.2.143 | 11 / 3 | |
| 3.2.142 | 11 / 3 | |
| 3.2.141 | 11 / 3 | |
| 3.2.140 | 11 / 3 |
v3.2.198
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.197
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.196
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.194
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.193
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.191
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.190
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.189
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.187
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.186
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.185
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.184
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.183
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.182
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.181
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.180
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.178
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.177
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.176
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.175
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.174
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.173
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.172
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.171
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.170
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.169
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.168
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.167
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.163
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.162
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.161
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.160
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.159
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.158
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.157
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.155
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.154
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.153
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.152
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.151
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.149
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.148
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.147
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.146
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.145
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.144
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.143
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.142
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.141
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.140
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.