← Home

markmap-lib

1
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

gera2ld

Keywords

markdownmarkmapmindmap

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:prismjs AI (dependencies): prismjs is a well-known syntax highlighting library; legitimate dependency for a Markdown rendering tool. ai
dependencies unvetted-dep:markdown-it AI (dependencies): markdown-it is the canonical Markdown parser for Node.js; expected dependency for markmap-lib. ai
dependencies unvetted-dep:markmap-view AI (dependencies): markmap-view is part of the same markmap monorepo by the same author; legitimate sibling dependency. ai
dependencies unvetted-dep:markdown-it-ins AI (dependencies): markdown-it-ins is a standard markdown-it plugin; legitimate dependency for a Markdown rendering tool. ai
dependencies unvetted-dep:markdown-it-sub AI (dependencies): markdown-it-sub is a standard markdown-it plugin; legitimate dependency for a Markdown rendering tool. ai
dependencies unvetted-dep:markdown-it-sup AI (dependencies): markdown-it-sup is a standard markdown-it plugin; legitimate dependency for a Markdown rendering tool. ai
dependencies unvetted-dep:markdown-it-mark AI (dependencies): markdown-it-mark is a standard markdown-it plugin; legitimate dependency for a Markdown rendering tool. ai
dependencies unvetted-dep:markmap-html-parser AI (dependencies): markmap-html-parser is part of the same markmap monorepo by the same author; legitimate sibling dependency. ai
dependencies unvetted-dep:@vscode/markdown-it-katex AI (dependencies): @vscode/markdown-it-katex is a Microsoft VSCode-maintained markdown-it plugin for KaTeX math rendering; legitimate dependency. ai
phantom-deps phantom-dep:katex AI (phantom-deps): katex is listed as a runtime dep and used via @vscode/markdown-it-katex; Vite bundling may explain the phantom detection. ai
phantom-deps phantom-dep:prismjs AI (phantom-deps): prismjs is a legitimate dependency loaded by convention/config in this bundled library; not a security concern. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): @babel/runtime is a framework-scoped package loaded by convention in Babel-transpiled output; expected pattern. ai

Versions (showing 1 of 1)

Version Deps Published
0.18.12 13 / 5

v0.18.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.