← Home

hast-util-from-html

hast utility to parse from HTML

1
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

wooormkmck

Keywords

unisthasthast-utilutilutilityhtmlparsetokenize

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:devlop AI (dependencies): devlop is a legitimate wooorm-authored utility used across the unified/hast ecosystem; not a risk for this package. ai
dependencies unvetted-dep:@types/hast AI (dependencies): @types/hast is the standard TypeScript types package for hast, maintained by the same ecosystem; not a risk. ai
phantom-deps phantom-dep:@types/hast AI (phantom-deps): @types/hast is a TypeScript types package; its use as a runtime dep for type re-export is a common pattern in this ecosystem. ai
bogus-package bogus-package AI (bogus-package): Mass-production signal references wrong maintainer (kmck vs wooorm); inflated semver is explained by ecosystem versioning conventions. Not indicative of spam or malice. ai

Versions (showing 1 of 1)

Version Deps Published
2.0.3 6 / 13