← Home

docz-theme-default

The default theme of docz

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

pedronauck

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata no-description AI (npm-metadata): Missing description is a minor metadata issue; package name and purpose are clear from context and version history. ai
phantom-deps phantom-dep:emotion-normalize AI (phantom-deps): emotion-normalize is a build-time dependency for emotion theming; phantom-dep is expected for theme packages. ai
phantom-deps phantom-dep:history AI (phantom-deps): history is a legitimate peer/build dependency for a React theme package; phantom-dep is expected here. ai
source-diff obfuscated-file:dist/index.m.js AI (source-diff): dist/index.m.js is a standard minified ES module bundle produced by libundler; the content is readable concatenated imports of well-known deps with no obfuscation or malicious patterns. ai
phantom-deps phantom-dep:react-feather AI (phantom-deps): react-feather is a declared runtime dependency; phantom-dep is a false positive for this theme package. ai
phantom-deps phantom-dep:react-spinners AI (phantom-deps): react-spinners is a declared runtime dependency; phantom-dep is a false positive for this theme package. ai
phantom-deps phantom-dep:emotion AI (phantom-deps): emotion is a declared runtime dependency in a theme package; phantom-dep signal is a false positive for this build/config pattern. ai
phantom-deps phantom-dep:prismjs AI (phantom-deps): prismjs is a declared runtime dependency used for syntax highlighting in this theme; phantom-dep is a false positive. ai
phantom-deps phantom-dep:react-emotion AI (phantom-deps): react-emotion is a declared runtime dependency; phantom-dep is a false positive for this theme package. ai
phantom-deps phantom-dep:emotion-theming AI (phantom-deps): emotion-theming is a declared runtime dependency; phantom-dep is a false positive for this theme package. ai
phantom-deps phantom-dep:fast-deep-equal AI (phantom-deps): fast-deep-equal is a declared runtime dependency; phantom-dep is a false positive for this theme package. ai
phantom-deps phantom-dep:react-powerplug AI (phantom-deps): react-powerplug is a declared runtime dependency; phantom-dep is a false positive for this theme package. ai
phantom-deps phantom-dep:react-lightweight-tooltip AI (phantom-deps): react-lightweight-tooltip is a declared runtime dependency; phantom-dep is a false positive for this theme package. ai
dependencies unvetted-dep:prismjs AI (dependencies): prismjs is a well-known, widely-used syntax highlighting library with no active advisories; unvetted-dep signal is a false positive here. ai
publish-pattern new-deps-added AI (publish-pattern): New deps (lodash, @reach/router, styled-components, etc.) are all established packages added as part of a documented major-version architectural migration from Emotion to styled-components. ai
bogus-package bogus-package AI (bogus-package): Missing repo/homepage is typical of monorepo sub-packages; this is a legitimate Docz ecosystem package by the original author with inbound approved edges. ai
phantom-deps phantom-dep:@tippy.js/react AI (phantom-deps): May be used indirectly or in config; false positive for this theme package given the legitimate publisher context. ai
phantom-deps phantom-dep:prop-types AI (phantom-deps): prop-types is a standard React ecosystem dep; phantom detection is a false positive for this theme package. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom is a standard React peer/runtime dep; phantom detection is a false positive for this theme package. ai

Versions (showing 51 of 51)

Version Deps Published
1.2.0 20 / 6
1.1.0 20 / 6
1.0.4 19 / 5
1.0.3 19 / 5
1.0.2 19 / 5
1.0.1 19 / 5
1.0.0 19 / 4
0.13.7 24 / 0
0.13.6 24 / 0
0.13.5 24 / 0
0.13.4 24 / 0
0.13.3 24 / 0
0.13.2 24 / 0
0.13.1 24 / 0
0.13.0 24 / 0
0.12.17 24 / 6
0.12.16 24 / 6
0.12.15 24 / 6
0.12.14 24 / 6
0.12.13 24 / 16
0.12.12 25 / 16
0.12.11 25 / 16
0.12.10 25 / 16
0.12.9 26 / 16
0.12.8 26 / 16
0.12.7 26 / 16
0.12.6 26 / 16
0.12.5 26 / 16
0.12.4 26 / 16
0.12.3 26 / 16
0.12.2 26 / 16
0.11.2 24 / 13
0.11.1 24 / 13
0.11.0 23 / 13
0.10.3 24 / 5
0.10.2 24 / 5
0.10.1 24 / 5
0.10.0 24 / 5
0.9.6 22 / 5
0.9.5 22 / 5
0.9.4 22 / 5
0.9.3 22 / 5
0.9.2 22 / 5
0.9.1 22 / 5
0.9.0 22 / 5
0.8.0 22 / 5
0.7.1 20 / 4
0.7.0 20 / 4
0.2.8 13 / 3
0.2.3 13 / 3
0.1.1 15 / 4

v1.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.14

2 findings
HIGH New obfuscated file: dist/index.m.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.