← Home

remark-mdc

6
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

farnabaz

Keywords

remarkmdc

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:micromark AI (phantom-deps): Core markdown parser; directly used in plugin implementation. ai
phantom-deps phantom-dep:@types/mdast AI (phantom-deps): TypeScript type definitions loaded by convention in remark ecosystem. ai
phantom-deps phantom-dep:@types/unist AI (phantom-deps): TypeScript type definitions loaded by convention in remark ecosystem. ai
phantom-deps phantom-dep:mdast-util-from-markdown AI (phantom-deps): Core markdown AST utility; directly used in plugin implementation. ai
phantom-deps phantom-dep:unist-util-visit-parents AI (phantom-deps): Core AST traversal utility; directly used in plugin implementation. ai

Versions (showing 6 of 6)

Version Deps Published
3.11.0 18 / 20
3.10.0 18 / 20
3.9.0 18 / 19
3.8.1 18 / 19
3.8.0 18 / 19
3.7.0 18 / 19

v3.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.