← Home

md4x

21
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

pi0

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:dynamic-require AI (semgrep): Standard NAPI platform-specific binary loader pattern; stable for this package. ai
npm-metadata bundled-binaries AI (npm-metadata): md4x ships prebuilt NAPI binaries for multiple platforms as its core feature; expected and attested via SLSA provenance. ai
typosquat typosquat.levenshtein:mobx AI (typosquat): md4x is a markdown parser from unjs org; no plausible impersonation of mobx (state management lib). ai
semgrep semgrep:toplevel-fetch AI (semgrep): fetch() in cli.mjs is for fetching remote markdown input URLs — documented CLI feature, not exfiltration. ai

Versions (showing 21 of 21)

Version Deps Published
0.0.25 0 / 4
0.0.24 0 / 4
0.0.23 0 / 4
0.0.22 0 / 4
0.0.21 0 / 4
0.0.20 0 / 4
0.0.19 0 / 4
0.0.18 0 / 4
0.0.17 0 / 4
0.0.16 0 / 4
0.0.15 0 / 4
0.0.12 0 / 4
0.0.11 0 / 4
0.0.10 0 / 4
0.0.9 0 / 4
0.0.7 0 / 4
0.0.5 0 / 4
0.0.4 0 / 8
0.0.3 0 / 8
0.0.2 0 / 8
0.0.1 0 / 8

v0.0.25

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.24

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.23

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.22

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.21

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.20

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.19

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.18

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.17

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.16

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.15

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.12

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.11

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.10

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.9

2 findings
HIGH Bundled binary files (9) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm.node • build/md4x.linux-arm64-musl.node • build/md4x.linux-arm64.node • build/md4x.linux-x64-musl.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.7

2 findings
HIGH Bundled binary files (6) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm64.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.5

2 findings
HIGH Bundled binary files (6) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm64.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.4

2 findings
HIGH Bundled binary files (6) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm64.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

2 findings
HIGH Bundled binary files (6) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm64.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

2 findings
HIGH Bundled binary files (6) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm64.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

2 findings
HIGH Bundled binary files (6) npm-metadata

Package contains compiled binaries that could be backdoors: • build/md4x.darwin-arm64.node • build/md4x.darwin-x64.node • build/md4x.linux-arm64.node • build/md4x.linux-x64.node • build/md4x.win32-arm64.node • build/md4x.win32-x64.node

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.