← Home

hast-util-to-estree

hast utility to transform to estree (JavaScript AST) JSX

1
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

wooormkmck

Keywords

changeecmascriptestreehast-utilhasthtmljavascriptjsxmdxrehypetransformunistutilityutil

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/hast AI (phantom-deps): TypeScript type package declared as a runtime dep to provide types for downstream TS consumers — standard pattern for unified/syntax-tree packages. ai
phantom-deps phantom-dep:@types/estree AI (phantom-deps): TypeScript type package declared as a runtime dep to provide types for downstream TS consumers — standard pattern for unified/syntax-tree packages. ai
phantom-deps phantom-dep:@types/estree-jsx AI (phantom-deps): TypeScript type package declared as a runtime dep to provide types for downstream TS consumers — standard pattern for unified/syntax-tree packages. ai
bogus-package bogus-package AI (bogus-package): Inflated semver reflects real development history of an established package; kmck mass-production signal is a false positive as actual publisher is wooorm (Titus Wormer), a trusted ecosystem maintainer. ai

Versions (showing 1 of 1)

Version Deps Published
3.1.3 16 / 18