← Home

@docusaurus/plugin-content-docs

Docs plugin for Docusaurus.

31
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

fbslorberlex111docusaurus-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Spam signals are false positives: 'fb' is legitimate Facebook/Docusaurus org; no-keywords is minor metadata issue. ai
source-diff large-new-source-files AI (source-diff): 30 new files in canary release is expected development activity; no obfuscation or malware indicators. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are all established Docusaurus ecosystem packages; no suspicious additions. ai
provenance publisher-changed AI (provenance): Publisher transition from docusaurus-bot to slorber is consistent with legitimate maintainer handoff within the same organization. ai
dependencies unvetted-dep:schema-dts AI (dependencies): schema-dts is a legitimate, pinned dependency for JSON schema type generation; stable for this package. ai
dependencies unvetted-dep:@docusaurus/module-type-aliases AI (dependencies): Sibling package in the same @docusaurus org scope, published by the same maintainer team; no security concern. ai
dependencies unvetted-dep:webpack AI (dependencies): webpack is a standard build dependency for Docusaurus plugins; version constraint is reasonable. ai
provenance no-provenance AI (provenance): Acceptable for this established publisher; not a security blocker. ai
dependencies unvetted-dep:@types/react-router-config AI (dependencies): Type definitions for react-router-config; standard dev/peer dependency for routing support. ai
phantom-deps phantom-dep:@docusaurus/module-type-aliases AI (phantom-deps): Same-org scoped dependency; expected phantom dep pattern for Docusaurus plugins. ai
phantom-deps phantom-dep:@docusaurus/core AI (phantom-deps): Same-org scoped dependency; expected phantom dep pattern for Docusaurus plugins. ai
phantom-deps phantom-dep:@types/react-router-config AI (phantom-deps): Framework-scoped type definition; expected phantom dep pattern for React-based plugins. ai

Versions (showing 31 of 31)

Show 23 prereleases
Version Deps Published
3.10.1 18 / 4
3.9.2 18 / 4
3.8.1 18 / 4
3.8.0 18 / 4
3.7.0 17 / 5
3.6.3 17 / 5
3.6.2 17 / 5
3.6.1 17 / 5
3.6.0 17 / 5
3.5.2 17 / 5
3.5.1 17 / 5
3.5.0 17 / 5
3.4.0 16 / 5
3.3.2 16 / 5
3.3.1 16 / 5
3.3.0 16 / 5
3.2.1 16 / 5
3.2.0 16 / 5
3.1.1 15 / 5
3.1.0 15 / 5
3.0.1 15 / 5
3.0.0 15 / 5
2.4.3 16 / 5
2.4.1 16 / 5
2.4.0 16 / 5
2.3.1 16 / 5
2.3.0 16 / 5
2.2.0 16 / 6
2.1.0 16 / 6
2.0.1 16 / 7
2.0.0 16 / 7

v3.10.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.8.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: docusaurus-bot → slorber (on 2025-05-27) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-05-27. This could indicate a legitimate maintainer transition or an account compromise.

v3.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.6.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.6.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.