zudoku
Framework for building high quality, interactive API documentation.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): Active framework with frequent releases; @base-ui/react is a legitimate MUI-backed UI library. | ai | |
| dependencies | unvetted-dep:@zuplo/mcp | AI (dependencies): First-party Zuplo package; same org as zudoku publisher. | ai | |
| dependencies | unvetted-dep:@zudoku/httpsnippet | AI (dependencies): Scoped to @zudoku org; expected dependency for this framework. | ai | |
| dependencies | unvetted-dep:@zudoku/react-helmet-async | AI (dependencies): Scoped to @zudoku org; expected dependency for this framework. | ai | |
| dependencies | unvetted-dep:@radix-ui/react-hover-card | AI (dependencies): Radix UI is a well-known UI library; consistent with other @radix-ui deps already in use. | ai | |
| dependencies | unvetted-dep:remark-comment | AI (dependencies): Small remark plugin; consistent with MDX/markdown processing use case. | ai | |
| dependencies | unvetted-dep:remark-directive-rehype | AI (dependencies): Small remark/rehype plugin; consistent with MDX/markdown processing use case. | ai | |
| dependencies | unvetted-dep:rehype-mdx-import-media | AI (dependencies): Rehype plugin for MDX; consistent with framework's markdown processing. | ai | |
| dependencies | unvetted-dep:@lekoarts/rehype-meta-as-attributes | AI (dependencies): Rehype plugin from known Gatsby/MDX ecosystem author; consistent use case. | ai | |
| dependencies | unvetted-dep:@pothos/core | AI (dependencies): GraphQL schema builder; consistent with graphql/graphql-yoga deps in this package. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Vite config loader merging prefixed env vars into process.env; standard pattern for this framework, not exfiltration. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Reads process.env keys filtered by envPrefix — standard Vite env loading pattern for this config framework. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): Referenced in config files by convention; stable false positive for this CSS framework package. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Framework-scoped type package; loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:tw-animate-css | AI (phantom-deps): CSS utility referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/react-dom | AI (phantom-deps): Framework-scoped type package; loaded by convention. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-toggle | AI (phantom-deps): Config-referenced UI component; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/typography | AI (phantom-deps): Config-referenced CSS plugin; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-toggle-group | AI (phantom-deps): Config-referenced UI component; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:json-schema-to-typescript-lite | AI (phantom-deps): Config-referenced utility; stable false positive for this package. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 0.82.1 | 121 / 26 | |
| 0.82.0 | 121 / 25 | |
| 0.81.0 | 121 / 25 | |
| 0.80.1 | 121 / 25 | |
| 0.80.0 | 121 / 25 | |
| 0.79.1 | 123 / 25 | |
| 0.79.0 | 120 / 25 | |
| 0.78.2 | 120 / 25 | |
| 0.78.1 | 120 / 25 | |
| 0.78.0 | 118 / 25 | |
| 0.77.0 | 118 / 25 | |
| 0.76.0 | 118 / 25 | |
| 0.75.1 | 119 / 25 | |
| 0.75.0 | 118 / 25 | |
| 0.74.2 | 118 / 25 | |
| 0.74.1 | 118 / 25 | |
| 0.74.0 | 118 / 25 | |
| 0.73.2 | 118 / 25 | |
| 0.73.1 | 118 / 25 | |
| 0.73.0 | 118 / 25 | |
| 0.72.0 | 118 / 25 | |
| 0.71.10 | 118 / 25 | |
| 0.71.9 | 118 / 24 | |
| 0.71.8 | 117 / 25 | |
| 0.71.7 | 117 / 25 | |
| 0.71.6 | 117 / 25 | |
| 0.71.5 | 117 / 25 | |
| 0.71.2 | 117 / 25 | |
| 0.71.0 | 117 / 25 | |
| 0.70.0 | 116 / 26 |
v0.82.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.82.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.80.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.80.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.79.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.79.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.78.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.78.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.78.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.77.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.74.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.74.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.74.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.73.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.73.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.73.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.72.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.71.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.71.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.71.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.71.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.71.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.71.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.71.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.71.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.