showdown
1
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
tiviesyntaxrules
Keywords
markdownconverter
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): yargs used by bin CLI, not a security concern. | ai | |
| provenance | no-provenance | AI (provenance): Showdown is a well-established package; lack of Sigstore provenance is common and not a meaningful risk signal here. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): The dynamic-require findings in bin/showdown.js are false positives — the requires are for static, known modules (fs, path, commander) in a minified CLI entry point. No user-controlled dynamic loading. | ai |
Versions (showing 1 of 1)
| Version | Deps | Published |
|---|---|---|
| 2.0.1 | 1 / 19 |
v2.0.1
2 findings
MEDIUM
GHSA-rmmh-p597-ppvv: Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing
osv
CVSS 5.3 (MEDIUM) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Showdownjs, versions <= 2.1.0, `anchors` subparser used to parse links has a nested regular expression which can lead to denial of service conditions given malicious input.
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.