← Home

remark-mdx-remove-esm

7
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

talatkuyuk

Keywords

unifiedmdastmarkdownMDXremarkpluginremark pluginmdxjsEsmmdx remove esmmdx remove mdxjsEsm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@types/mdast AI (dependencies): @types/mdast is a standard DefinitelyTyped package; no security risk. ai
phantom-deps phantom-dep:@types/mdast AI (phantom-deps): @types/mdast is a TypeScript type package from the unified ecosystem; phantom detection is expected as it provides ambient types rather than direct imports. ai
phantom-deps phantom-dep:mdast-util-mdxjs-esm AI (phantom-deps): mdast-util-mdxjs-esm is used for type augmentation/config in this remark plugin; not being directly imported is expected and benign. ai

Versions (showing 7 of 7)

Version Deps Published
1.3.2 2 / 24
1.3.1 3 / 23
1.3.0 3 / 23
1.2.3 3 / 23
1.2.2 3 / 23
1.2.1 3 / 23
1.2.0 3 / 23

v1.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.