remark-footnotes
Deprecated: this package is no longer maintained. Please use [`remark-gfm`][gfm] instead. That package match how footnotes work on github.com, which is more likely to match the expectations of authors.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@types/mdast | AI (dependencies): @types/mdast is a TypeScript type declaration package from DefinitelyTyped, standard in the unified/remark ecosystem. No runtime risk. | ai | |
| phantom-deps | phantom-dep:@types/mdast | AI (phantom-deps): @types/mdast is a TypeScript type definitions package legitimately declared as a runtime dep for consumer type inference in the unified ecosystem; not directly imported at runtime by convention. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): remcohaszing is a known contributor in the unified/remark ecosystem; addition is consistent with legitimate project collaboration under wooorm's stewardship. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Tiny payload and no deps are consistent with a deliberate deprecation/stub release pattern for a superseded package, not spam or malware. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Long dormancy followed by a stub/deprecation release is a normal lifecycle pattern for remark ecosystem packages; publisher wooorm has a strong trust record. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 5.0.0 | 0 / 0 | |
| 4.0.1 | 4 / 18 | |
| 4.0.0 | 4 / 19 | |
| 3.0.0 | 2 / 16 | |
| 2.0.0 | 0 / 15 | |
| 1.0.0 | 0 / 14 |
v5.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.