← Home

react-markdown

Renders Markdown as React components

94
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

johnowooormremcohaszing

Keywords

astcommonmarkcomponentgfmmarkdownreactreact-componentremarkunified

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/prop-types AI (phantom-deps): TypeScript type definitions loaded by framework convention; stable pattern for this package. ai
phantom-deps phantom-dep:@types/unist AI (phantom-deps): Framework-scoped TypeScript type definitions loaded by convention; stable pattern for this package. ai
source-diff large-new-source-files AI (source-diff): 25 new files reflect the addition of a webpack build pipeline, UMD distribution, demo app, and library refactor in v3.0.0. No injected payloads detected. ai
source-diff obfuscated-file:demo/dist/js/demo.js AI (source-diff): demo/dist/js/demo.js is a standard webpack-built demo bundle (UMD wrapping React/ReactDOM). Committed build artifact, not malicious obfuscation. Stable for this package. ai
source-diff source-size-tripled AI (source-diff): Size increase reflects a major version rewrite adding UMD builds, demo app, and remark/unified-based parser. Legitimate structural change for react-markdown. ai
source-diff obfuscated-file:umd/react-markdown.js AI (source-diff): umd/react-markdown.js is a standard webpack production bundle (UMD format). The minified output is expected for browser distribution and matches the package.json build script. Not obfuscated malware. ai
phantom-deps phantom-dep:in-publish AI (phantom-deps): in-publish is declared as a runtime dependency and used in prepublish script for conditional build logic; legitimate pattern for npm lifecycle hooks. ai
dependencies unvetted-dep:commonmark AI (dependencies): commonmark is the reference CommonMark parser and a legitimate, expected core dependency for react-markdown's documented functionality. ai
dependencies unvetted-dep:commonmark-react-renderer AI (dependencies): commonmark-react-renderer is the companion renderer for commonmark, a legitimate and expected dependency for this package's purpose. ai
phantom-deps phantom-dep:@types/hast AI (phantom-deps): Framework-scoped TypeScript type definitions loaded by convention; stable pattern for this package. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are coherent remark/rehype ecosystem packages; reflects intentional architectural refactoring for v8. ai
phantom-deps phantom-dep:@types/mdast AI (phantom-deps): TypeScript type packages are conventionally loaded without direct imports; stable pattern for this package. ai
phantom-deps phantom-dep:mdast-util-to-hast AI (phantom-deps): Dependency is referenced in config and used transitively; phantom status is expected for remark ecosystem packages. ai
maintainer-change maintainer-takeover AI (maintainer-change): Transition from rexxars to wooorm+johno is a legitimate handoff within the remark ecosystem; wooorm is a core trusted maintainer. ai
provenance publisher-changed AI (provenance): Publisher change reflects documented maintainer transition within the remark ecosystem; wooorm is a known trusted maintainer. ai
maintainer-change maintainer-added AI (maintainer-change): Maintainer transition within remarkjs ecosystem; wooorm is established ecosystem maintainer. ai
dependencies unvetted-dep:@types/mdast AI (dependencies): Official DefinitelyTyped package for mdast AST types; appropriate for TypeScript support in major version. ai
dependencies unvetted-dep:html-url-attributes AI (dependencies): Established utility for HTML URL attribute handling; appropriate for markdown-to-React rendering. ai
source-diff source-size-dropped AI (source-diff): 93% source reduction reflects intentional refactor to use remark/rehype composition instead of custom implementation; not a code-stripping attack. ai
dependencies unvetted-dep:devlop AI (dependencies): devlop is a small utility package in the remark ecosystem; unvetted status is expected for newer ecosystem packages. ai
maintainer-change maintainer-removed AI (maintainer-change): rexxars voluntarily transferred the package; original author is still listed in contributors. No hijack indicators. ai
dependencies unvetted-dep:@types/hast AI (dependencies): Standard type package with reasonable version constraint; part of established unified ecosystem. ai
dependencies unvetted-dep:html-to-react AI (dependencies): html-to-react is a legitimate, well-known utility for converting HTML to React components; expected dependency for a markdown renderer. ai
dependencies unvetted-dep:unist-util-visit AI (dependencies): unist-util-visit is a core utility in the unified ecosystem; its use is consistent with the package's modernization. ai
dependencies unvetted-dep:mdast-add-list-metadata AI (dependencies): mdast-add-list-metadata is a small, legitimate mdast utility; expected dependency for list rendering in react-markdown. ai
provenance no-provenance AI (provenance): Provenance is not yet standard practice; absence is not a security concern for this mature, trusted package. ai

Versions (showing 94 of 94)

Version Deps Published
10.1.0 11 / 21
10.0.1 11 / 19
10.0.0 11 / 19
9.1.0 11 / 19
9.0.3 10 / 17
9.0.2 10 / 17
9.0.1 10 / 17
9.0.0 11 / 17
8.0.7 15 / 22
8.0.6 15 / 22
8.0.5 15 / 23
8.0.4 15 / 23
8.0.3 15 / 23
8.0.2 15 / 23
8.0.1 15 / 23
8.0.0 14 / 23
7.1.2 14 / 23
7.1.1 14 / 23
7.1.0 14 / 23
7.0.1 13 / 23
7.0.0 13 / 23
6.0.3 13 / 41
6.0.2 13 / 41
6.0.1 12 / 41
6.0.0 12 / 41
5.0.3 10 / 37
5.0.2 10 / 37
5.0.1 10 / 37
5.0.0 10 / 37
4.3.1 8 / 29
4.3.0 8 / 29
4.2.2 8 / 29
4.2.1 8 / 29
4.2.0 8 / 29
4.1.0 7 / 28
4.0.9 7 / 28
4.0.8 7 / 28
4.0.7 7 / 28
4.0.6 7 / 26
4.0.5 7 / 26
4.0.4 7 / 26
4.0.3 7 / 26
4.0.2 7 / 26
4.0.1 7 / 26
4.0.0 7 / 26
3.6.0 6 / 22
3.5.0 6 / 22
3.4.1 6 / 21
3.4.0 6 / 21
3.3.4 5 / 21
3.3.3 5 / 21
3.3.2 5 / 21
3.3.1 5 / 21
3.3.0 5 / 20
3.2.2 5 / 19
3.2.1 5 / 19
3.2.0 5 / 19
3.1.5 5 / 19
3.1.4 5 / 19
3.1.3 5 / 19
3.1.2 5 / 19
3.1.1 5 / 19
3.1.0 5 / 19
3.0.2 5 / 19
3.0.1 5 / 19
3.0.0 5 / 18
2.5.1 3 / 16
2.5.0 4 / 16
2.4.6 3 / 17
2.4.5 3 / 17
2.4.4 3 / 17
2.4.3 3 / 17
2.4.2 3 / 16
2.4.1 3 / 16
2.4.0 3 / 21
2.3.0 3 / 21
2.2.0 3 / 21
2.1.1 3 / 21
2.1.0 3 / 21
2.0.1 3 / 21
2.0.0 3 / 19
1.2.4 3 / 19
1.2.3 3 / 19
1.2.2 3 / 19
1.2.1 3 / 19
1.2.0 3 / 19
1.1.4 3 / 19
1.1.3 3 / 19
1.1.1 2 / 18
1.1.0 2 / 18
1.0.5 2 / 17
1.0.3 3 / 14
1.0.1 3 / 8
1.0.0 3 / 8

v10.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.6

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rexxars → wooorm (on 2023-03-20) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-03-20. This could indicate a legitimate maintainer transition or an account compromise.

v8.0.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rexxars → wooorm (on 2021-04-23) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-04-23. This could indicate a legitimate maintainer transition or an account compromise.

v6.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.1

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rexxars → wooorm (on 2020-10-21) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-10-21. This could indicate a legitimate maintainer transition or an account compromise.

v5.0.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rexxars → wooorm (on 2020-10-19) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-10-19. This could indicate a legitimate maintainer transition or an account compromise.

v4.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.2

2 findings
HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.1

2 findings
HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.0

2 findings
HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.2

2 findings
HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.1

2 findings
HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.0

2 findings
HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.5

2 findings
HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.4

2 findings
HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.1.2

3 findings
HIGH New obfuscated file: demo/dist/js/demo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.1

3 findings
HIGH New obfuscated file: demo/dist/js/demo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

3 findings
HIGH New obfuscated file: demo/dist/js/demo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.2

3 findings
HIGH New obfuscated file: demo/dist/js/demo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.1

3 findings
HIGH New obfuscated file: demo/dist/js/demo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

3 findings
HIGH New obfuscated file: demo/dist/js/demo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: umd/react-markdown.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.