@activepieces/pieces-framework
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:object-sizeof | AI (phantom-deps): Likely used indirectly in compiled/bundled code; benign utility dep. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Common utility dep, likely missed by static import scan in transpiled output. | ai | |
| phantom-deps | phantom-dep:@sinclair/typebox | AI (phantom-deps): Type-only/config usage likely; established monorepo package with stable deps. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Legitimate base64-to-file conversion utility, not payload obfuscation. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Monorepo bot publisher with 25 approved packages; dormancy reflects release cadence, not account takeover. | ai | |
| phantom-deps | phantom-dep:ai | AI (phantom-deps): Framework peer/optional dep pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/replicate | AI (phantom-deps): Framework peer/optional dep pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/anthropic | AI (phantom-deps): Framework peer/optional dep pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/openai | AI (phantom-deps): Framework peer/optional dep pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:nanoid | AI (phantom-deps): Declared in package.json; heuristic false positive for config-referenced deps. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Declared in package.json; heuristic false positive for config-referenced deps. | ai | |
| phantom-deps | phantom-dep:deepmerge-ts | AI (phantom-deps): Declared in package.json; heuristic false positive for config-referenced deps. | ai | |
| phantom-deps | phantom-dep:socket.io-client | AI (phantom-deps): Declared in package.json; heuristic false positive for config-referenced deps. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable pattern across all versions of this monorepo package; not a malice signal. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo-published package; missing metadata fields are consistent across all versions, not a spam indicator. | ai | |
| phantom-deps | phantom-dep:lru-cache | AI (phantom-deps): Monorepo transitive dep declared in package.json; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/provider-utils | AI (phantom-deps): AI SDK peer dep declared for resolution; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@standard-schema/spec | AI (phantom-deps): Schema peer dep declared for resolution; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eventsource-parser | AI (phantom-deps): Streaming dep declared for resolution; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api | AI (phantom-deps): Observability peer dep declared for resolution; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/provider | AI (phantom-deps): AI SDK peer dep declared for resolution; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/gateway | AI (phantom-deps): AI SDK peer dep declared for resolution; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@vercel/oidc | AI (phantom-deps): Framework-scoped dep loaded by convention in the Activepieces ecosystem. | ai | |
| phantom-deps | phantom-dep:yallist | AI (phantom-deps): Monorepo transitive dep declared in package.json; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:json-schema | AI (phantom-deps): Monorepo transitive dep declared in package.json; not a direct import by design. | ai |
Versions (showing 46 of 146)
| Version | Deps | Published |
|---|---|---|
| 0.7.3 | 9 / 0 | |
| 0.7.2 | 9 / 0 | |
| 0.7.1 | 9 / 0 | |
| 0.7.0 | 9 / 0 | |
| 0.6.21 | 9 / 0 | |
| 0.6.20 | 9 / 0 | |
| 0.6.19 | 9 / 0 | |
| 0.6.18 | 9 / 0 | |
| 0.6.17 | 8 / 0 | |
| 0.6.16 | 8 / 0 | |
| 0.6.15 | 8 / 0 | |
| 0.6.14 | 9 / 0 | |
| 0.6.13 | 9 / 0 | |
| 0.6.12 | 9 / 0 | |
| 0.6.11 | 8 / 0 | |
| 0.6.10 | 8 / 0 | |
| 0.6.9 | 8 / 0 | |
| 0.6.8 | 8 / 0 | |
| 0.6.7 | 9 / 0 | |
| 0.6.6 | 5 / 0 | |
| 0.6.5 | 9 / 0 | |
| 0.6.4 | 5 / 0 | |
| 0.6.3 | 5 / 0 | |
| 0.6.2 | 5 / 0 | |
| 0.6.1 | 5 / 0 | |
| 0.6.0 | 5 / 0 | |
| 0.5.0 | 4 / 0 | |
| 0.4.0 | 4 / 0 | |
| 0.3.30 | 4 / 0 | |
| 0.3.29 | 5 / 0 | |
| 0.3.28 | 5 / 0 | |
| 0.3.27 | 5 / 0 | |
| 0.3.26 | 5 / 0 | |
| 0.3.25 | 5 / 0 | |
| 0.3.24 | 5 / 0 | |
| 0.3.23 | 5 / 0 | |
| 0.3.22 | 5 / 0 | |
| 0.3.21 | 5 / 0 | |
| 0.3.20 | 5 / 0 | |
| 0.3.19 | 5 / 0 | |
| 0.3.18 | 5 / 0 | |
| 0.3.17 | 4 / 0 | |
| 0.3.16 | 4 / 0 | |
| 0.3.15 | 4 / 0 | |
| 0.3.14 | 4 / 0 | |
| 0.3.13 | 4 / 0 |
v0.7.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.