@astrojs/markdown-remark
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Monorepo package from the official withastro/astro repo; missing description is a cosmetic issue, not a malware indicator. | ai | |
| dependencies | unvetted-dep:@astrojs/prism | AI (dependencies): @astrojs/prism is an official Astro framework package from the same withastro org; stable dependency for this package. | ai | |
| dependencies | unvetted-dep:remark-smartypants | AI (dependencies): remark-smartypants is a well-known, legitimate package in the unified/remark ecosystem; no risk for this package. | ai | |
| dependencies | unvetted-dep:retext-smartypants | AI (dependencies): retext-smartypants is a well-known, legitimate package in the unified/retext ecosystem; no risk for this package. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 7.2.0 | 17 / 8 | |
| 7.1.2 | 21 / 8 | |
| 7.1.1 | 21 / 8 | |
| 7.1.0 | 21 / 8 | |
| 7.0.1 | 20 / 8 | |
| 7.0.0 | 20 / 8 | |
| 6.3.11 | 21 / 8 | |
| 6.3.10 | 21 / 8 | |
| 6.3.9 | 21 / 8 |
v7.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.3.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.3.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.3.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.