← Home

remark-footnotes

Deprecated: this package is no longer maintained. Please use [`remark-gfm`][gfm] instead. That package match how footnotes work on github.com, which is more likely to match the expectations of authors.

6
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

remcohaszingjohnowooorm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@types/mdast AI (dependencies): @types/mdast is a TypeScript type declaration package from DefinitelyTyped, standard in the unified/remark ecosystem. No runtime risk. ai
phantom-deps phantom-dep:@types/mdast AI (phantom-deps): @types/mdast is a TypeScript type definitions package legitimately declared as a runtime dep for consumer type inference in the unified ecosystem; not directly imported at runtime by convention. ai
maintainer-change maintainer-added AI (maintainer-change): remcohaszing is a known contributor in the unified/remark ecosystem; addition is consistent with legitimate project collaboration under wooorm's stewardship. ai
bogus-package bogus-package AI (bogus-package): Tiny payload and no deps are consistent with a deliberate deprecation/stub release pattern for a superseded package, not spam or malware. ai
publish-pattern dormant-publish AI (publish-pattern): Long dormancy followed by a stub/deprecation release is a normal lifecycle pattern for remark ecosystem packages; publisher wooorm has a strong trust record. ai

Versions (showing 6 of 6)

Version Deps Published
5.0.0 0 / 0
4.0.1 4 / 18
4.0.0 4 / 19
3.0.0 2 / 16
2.0.0 0 / 15
1.0.0 0 / 14

v5.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.