rehype-docz
Rehype plugin used by docz
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): brace and react-ace are well-known Ace editor packages, consistent with docz's code editing functionality. Both are phantom deps (not directly imported), indicating they are declared for consumers. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Package is 2831 days old with 92 versions and 7.8k weekly downloads. Metadata hygiene issues (no repo URL, sparse README) are cosmetic and not indicative of malicious intent for this established package. | ai | |
| phantom-deps | phantom-dep:brace | AI (phantom-deps): brace is a declared dependency used in docz config/tooling context; phantom detection is a false positive for this monorepo sub-package. | ai | |
| phantom-deps | phantom-dep:react-ace | AI (phantom-deps): react-ace is a declared dependency used in docz config/tooling context; phantom detection is a false positive for this monorepo sub-package. | ai | |
| provenance | publisher-changed | AI (provenance): renatobenks is a known docz maintainer with 315 approved packages and 0 rejections; transition from rakannimer is a documented project handoff within doczjs org. | ai | |
| phantom-deps | phantom-dep:unist-util-is | AI (phantom-deps): unist-util-is is a declared dependency used in docz config/tooling context; phantom detection is a false positive for this monorepo sub-package. | ai | |
| phantom-deps | phantom-dep:jsx-ast-utils | AI (phantom-deps): jsx-ast-utils is a declared dependency used in docz config/tooling context; phantom detection is a false positive for this monorepo sub-package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): renatobenks is a legitimate docz project maintainer with a clean track record; addition reflects project ownership transition, not compromise. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 2.4.0 | 7 / 0 | |
| 2.3.0 | 7 / 4 | |
| 2.1.0 | 7 / 4 | |
| 2.0.0 | 7 / 4 | |
| 1.2.0 | 5 / 3 | |
| 1.1.0 | 5 / 3 | |
| 1.0.4 | 5 / 3 | |
| 1.0.2 | 5 / 3 | |
| 1.0.1 | 5 / 3 | |
| 1.0.0 | 5 / 2 | |
| 0.13.6 | 5 / 0 | |
| 0.13.5 | 5 / 0 | |
| 0.13.3 | 5 / 0 | |
| 0.13.0 | 5 / 0 | |
| 0.12.16 | 5 / 1 | |
| 0.12.15 | 5 / 1 | |
| 0.12.14 | 5 / 1 | |
| 0.12.13 | 5 / 1 | |
| 0.12.12 | 5 / 1 | |
| 0.12.10 | 5 / 1 | |
| 0.12.9 | 5 / 1 | |
| 0.12.8 | 5 / 1 | |
| 0.12.6 | 5 / 1 | |
| 0.12.2 | 5 / 1 | |
| 0.11.0 | 9 / 2 | |
| 0.10.3 | 9 / 2 | |
| 0.10.0 | 9 / 2 | |
| 0.9.4 | 7 / 0 | |
| 0.9.0 | 7 / 0 | |
| 0.8.0 | 7 / 0 | |
| 0.7.0 | 7 / 0 |
v2.4.0
2 findingsThis version was published by a different npm account than previous versions on 2022-02-11. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: rakannimer.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2019-11-25. This could indicate a legitimate maintainer transition or an account compromise.
v1.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.