← Home

@activepieces/pieces-framework

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

abuaboudactivepieces-botabdul_activepiecer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern dormant-publish AI (publish-pattern): Monorepo bot publisher with 25 approved packages; dormancy reflects release cadence, not account takeover. ai
phantom-deps phantom-dep:@ai-sdk/replicate AI (phantom-deps): Framework peer/optional dep pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@ai-sdk/anthropic AI (phantom-deps): Framework peer/optional dep pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@ai-sdk/openai AI (phantom-deps): Framework peer/optional dep pattern; stable false positive for this package. ai
phantom-deps phantom-dep:ai AI (phantom-deps): Framework peer/optional dep pattern; stable false positive for this package. ai
phantom-deps phantom-dep:semver AI (phantom-deps): Declared in package.json; heuristic false positive for config-referenced deps. ai
phantom-deps phantom-dep:socket.io-client AI (phantom-deps): Declared in package.json; heuristic false positive for config-referenced deps. ai
phantom-deps phantom-dep:deepmerge-ts AI (phantom-deps): Declared in package.json; heuristic false positive for config-referenced deps. ai
phantom-deps phantom-dep:nanoid AI (phantom-deps): Declared in package.json; heuristic false positive for config-referenced deps. ai
bogus-package bogus-package AI (bogus-package): Monorepo-published package; missing metadata fields are consistent across all versions, not a spam indicator. ai
npm-metadata no-description AI (npm-metadata): Stable pattern across all versions of this monorepo package; not a malice signal. ai
phantom-deps phantom-dep:lru-cache AI (phantom-deps): Monorepo transitive dep declared in package.json; not a direct import by design. ai
phantom-deps phantom-dep:@ai-sdk/provider-utils AI (phantom-deps): AI SDK peer dep declared for resolution; stable false positive for this package. ai
phantom-deps phantom-dep:@standard-schema/spec AI (phantom-deps): Schema peer dep declared for resolution; stable false positive for this package. ai
phantom-deps phantom-dep:eventsource-parser AI (phantom-deps): Streaming dep declared for resolution; stable false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/api AI (phantom-deps): Observability peer dep declared for resolution; stable false positive for this package. ai
phantom-deps phantom-dep:@ai-sdk/provider AI (phantom-deps): AI SDK peer dep declared for resolution; stable false positive for this package. ai
phantom-deps phantom-dep:@ai-sdk/gateway AI (phantom-deps): AI SDK peer dep declared for resolution; stable false positive for this package. ai
phantom-deps phantom-dep:@vercel/oidc AI (phantom-deps): Framework-scoped dep loaded by convention in the Activepieces ecosystem. ai
phantom-deps phantom-dep:json-schema AI (phantom-deps): Monorepo transitive dep declared in package.json; not a direct import by design. ai
phantom-deps phantom-dep:yallist AI (phantom-deps): Monorepo transitive dep declared in package.json; not a direct import by design. ai

Versions (showing 51 of 54)

View all versions
Version Deps Published
0.30.0 5 / 2
0.29.1 5 / 2
0.29.0 5 / 2
0.28.2 5 / 2
0.28.1 5 / 2
0.28.0 5 / 2
0.27.2 15 / 2
0.27.1 15 / 2
0.27.0 15 / 2
0.26.2 5 / 2
0.26.1 5 / 2
0.26.0 5 / 2
0.25.6 5 / 2
0.25.5 5 / 2
0.25.4 8 / 0
0.25.3 9 / 0
0.25.2 9 / 0
0.25.1 9 / 0
0.25.0 9 / 0
0.24.0 11 / 0
0.23.0 7 / 0
0.22.3 7 / 0
0.22.2 7 / 0
0.22.1 7 / 0
0.22.0 7 / 0
0.21.0 7 / 0
0.20.3 7 / 0
0.20.2 6 / 0
0.20.1 6 / 0
0.20.0 6 / 0
0.19.0 6 / 0
0.18.5 7 / 0
0.18.4 7 / 0
0.18.3 12 / 0
0.18.2 12 / 0
0.18.1 12 / 0
0.18.0 12 / 0
0.17.0 12 / 0
0.16.0 12 / 0
0.15.0 12 / 0
0.14.2 12 / 0
0.14.1 11 / 0
0.14.0 7 / 0
0.13.0 7 / 0
0.12.0 7 / 0
0.11.0 7 / 0
0.10.5 7 / 0
0.10.4 7 / 0
0.10.3 6 / 0
0.10.2 7 / 0
0.10.1 7 / 0

v0.30.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.28.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.28.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.28.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.27.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.27.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.26.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.26.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.25.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.25.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.25.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.25.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.20.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.20.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.