unist-util-visit-parents
unist utility to recursively walk over nodes, with ancestral information
3
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
wooormkmck
Keywords
unistunist-utilutilutilitytreeastvisittraversewalkcheckparentparents
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): The dormancy is an artifact of comparing against a very old approved version (v1.1.2). wooorm has published many versions of this package; the gap reflects review lag, not account takeover. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @types/unist and unist-util-is are core unified ecosystem packages; their addition is expected for a TypeScript-modernized major version of this utility. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects TypeScript migration, ESM module structure, and type definitions — not injected payloads. Consistent with a major version bump. | ai | |
| phantom-deps | phantom-dep:@types/unist | AI (phantom-deps): @types/unist is a TypeScript type-only package; not directly imported in JS but legitimately declared as a runtime dep for TypeScript consumers. | ai |
v6.0.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.