@mintlify/prebuild
Helpful functions for Mintlify's prebuild step
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers are Mintlify employees (ruhanponnada, kathrynmintlify, kylefinken); org-internal change. | ai | |
| license | uncommon-license:Elastic-2.0 | AI (license): Elastic-2.0 is Mintlify's standard license across their packages. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from individual account to GitHub Actions CI publishing; consistent with org CI/CD migration. | ai | |
| phantom-deps | phantom-dep:gray-matter | AI (phantom-deps): gray-matter is referenced in config files but not directly imported; consistent with other accepted phantom deps in this package. | ai | |
| provenance | no-provenance | AI (provenance): Provenance attestation is uncommon across npm (~12%); absence is not a security disqualifier for this established package. | ai | |
| phantom-deps | phantom-dep:front-matter | AI (phantom-deps): Legitimate package; phantom detection likely due to indirect/type-level usage in a TypeScript build context. | ai | |
| dependencies | unvetted-dep:favicons | AI (dependencies): favicons is a well-known, legitimate favicon generation library; appropriate dependency for a documentation prebuild tool. | ai | |
| dependencies | unvetted-dep:sharp-ico | AI (dependencies): sharp-ico is a legitimate ICO format plugin for the sharp image library, which is also a direct dep; appropriate for favicon/image processing in prebuild. | ai | |
| phantom-deps | phantom-dep:openapi-types | AI (phantom-deps): Legitimate types-only package; phantom detection expected for type-only imports in TypeScript projects. | ai | |
| phantom-deps | phantom-dep:unist-util-visit | AI (phantom-deps): Legitimate unist utility; phantom detection likely due to indirect usage pattern in TypeScript build. | ai | |
| dependencies | unvetted-dep:@mintlify/common | AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. | ai | |
| phantom-deps | phantom-dep:@mintlify/openapi-parser | AI (phantom-deps): Same-org package; phantom dep finding is a code quality note, not a security risk for this package. | ai | |
| dependencies | unvetted-dep:@mintlify/openapi-parser | AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. | ai | |
| dependencies | unvetted-dep:@mintlify/validation | AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. | ai | |
| dependencies | unvetted-dep:@mintlify/scraping | AI (dependencies): Same-org scoped package from Mintlify; expected internal dependency across all @mintlify/* packages. | ai |
Versions (showing 51 of 548)
| Version | Deps | Published |
|---|---|---|
| 1.0.1061 | 14 / 12 | |
| 1.0.1060 | 14 / 12 | |
| 1.0.1059 | 14 / 12 | |
| 1.0.1058 | 14 / 12 | |
| 1.0.1057 | 14 / 12 | |
| 1.0.1056 | 14 / 12 | |
| 1.0.1055 | 14 / 12 | |
| 1.0.1054 | 14 / 12 | |
| 1.0.1053 | 14 / 12 | |
| 1.0.1052 | 14 / 14 | |
| 1.0.1051 | 14 / 14 | |
| 1.0.1050 | 14 / 14 | |
| 1.0.1049 | 14 / 14 | |
| 1.0.1048 | 14 / 14 | |
| 1.0.1047 | 14 / 14 | |
| 1.0.1046 | 14 / 14 | |
| 1.0.1045 | 14 / 14 | |
| 1.0.1044 | 14 / 14 | |
| 1.0.1043 | 14 / 14 | |
| 1.0.1042 | 14 / 14 | |
| 1.0.1041 | 14 / 14 | |
| 1.0.1040 | 14 / 14 | |
| 1.0.1039 | 14 / 14 | |
| 1.0.1038 | 14 / 14 | |
| 1.0.1037 | 14 / 14 | |
| 1.0.1036 | 14 / 14 | |
| 1.0.1035 | 14 / 14 | |
| 1.0.1034 | 14 / 14 | |
| 1.0.1033 | 14 / 14 | |
| 1.0.1032 | 14 / 14 | |
| 1.0.1031 | 14 / 14 | |
| 1.0.1030 | 14 / 14 | |
| 1.0.1029 | 14 / 14 | |
| 1.0.1028 | 14 / 14 | |
| 1.0.1027 | 14 / 14 | |
| 1.0.1026 | 14 / 14 | |
| 1.0.1025 | 14 / 14 | |
| 1.0.1024 | 14 / 14 | |
| 1.0.1023 | 14 / 14 | |
| 1.0.1022 | 14 / 14 | |
| 1.0.1021 | 14 / 14 | |
| 1.0.1020 | 14 / 14 | |
| 1.0.1019 | 14 / 14 | |
| 1.0.1018 | 14 / 14 | |
| 1.0.1017 | 14 / 14 | |
| 1.0.1016 | 14 / 14 | |
| 1.0.1015 | 14 / 14 | |
| 1.0.1014 | 14 / 14 | |
| 1.0.1013 | 14 / 14 | |
| 1.0.1012 | 14 / 14 | |
| 1.0.1011 | 14 / 14 |
v1.0.1061
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1060
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1059
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1058
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1057
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1056
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1055
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1054
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1053
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1052
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1051
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1050
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1049
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1048
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1047
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1046
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1045
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1044
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1043
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1042
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1041
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1040
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1039
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1038
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1037
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1036
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1035
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1034
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1033
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1032
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1031
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1030
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1029
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1028
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1027
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1026
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1025
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1024
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1023
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1022
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1021
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1020
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1019
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1018
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1017
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1016
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1015
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1014
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1013
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1012
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1011
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.