← Home

@activepieces/pieces-common

33
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

abuaboudactivepieces-botabdul_activepiecer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:fast-glob AI (phantom-deps): Same monorepo re-export pattern as other accepted phantom deps. ai
phantom-deps phantom-dep:@ai-sdk/anthropic AI (phantom-deps): Same monorepo re-export pattern as other accepted phantom deps. ai
phantom-deps phantom-dep:@ai-sdk/replicate AI (phantom-deps): Same monorepo re-export pattern as other accepted phantom deps. ai
phantom-deps phantom-dep:ai AI (phantom-deps): Monorepo build pattern; re-exported via index, not directly imported. Consistent with other accepted phantom deps in this package. ai
phantom-deps phantom-dep:@ai-sdk/openai AI (phantom-deps): Same monorepo re-export pattern as other accepted phantom deps. ai
phantom-deps phantom-dep:socket.io-client AI (phantom-deps): Declared in package.json; used indirectly via framework modules. ai
phantom-deps phantom-dep:nanoid AI (phantom-deps): Declared in package.json; used indirectly via framework modules. ai
phantom-deps phantom-dep:semver AI (phantom-deps): Declared in package.json; used indirectly via framework modules. ai
phantom-deps phantom-dep:deepmerge-ts AI (phantom-deps): Declared in package.json; used indirectly via framework modules. ai
phantom-deps phantom-dep:@sinclair/typebox AI (phantom-deps): Declared in package.json; used indirectly via framework modules. ai
dependencies unvetted-dep:@activepieces/shared AI (dependencies): Sibling package within the @activepieces monorepo; expected internal dependency. ai
bogus-package bogus-package AI (bogus-package): Monorepo-published package; missing metadata is a build artifact pattern, not spam. ai
dependencies unvetted-dep:@activepieces/pieces-framework AI (dependencies): Sibling package within the @activepieces monorepo; expected internal dependency. ai

Versions (showing 33 of 33)

Version Deps Published
0.12.1 9 / 1
0.12.0 8 / 1
0.11.7 8 / 1
0.11.6 14 / 0
0.11.5 15 / 0
0.11.4 15 / 0
0.11.3 15 / 0
0.11.2 17 / 0
0.11.1 13 / 0
0.11.0 13 / 0
0.10.2 12 / 0
0.10.1 12 / 0
0.10.0 12 / 0
0.9.0 12 / 0
0.8.2 12 / 0
0.8.1 11 / 0
0.7.0 12 / 0
0.6.7 18 / 0
0.6.6 18 / 0
0.6.5 18 / 0
0.6.4 17 / 0
0.6.3 17 / 0
0.6.2 17 / 0
0.6.1 17 / 0
0.6.0 17 / 0
0.5.2 16 / 0
0.5.1 16 / 0
0.5.0 16 / 0
0.4.10 16 / 0
0.4.8 15 / 0
0.4.7 15 / 0
0.4.6 14 / 0
0.4.5 14 / 0

v0.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.