@agentskit/tools
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@agentskit/core | AI (dependencies): First-party sibling package within same monorepo/org, pinned to exact version. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Growth explained by added first-party dependency and its sourcemaps, not a payload. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is the package's own sibling @agentskit/integrations, first-party. | ai | |
| provenance | no-provenance | AI (provenance): No CI provenance configured for this package; consistent across versions, not a security defect on its own. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 0.11.11 | 2 / 7 | |
| 0.11.10 | 2 / 7 | |
| 0.11.9 | 2 / 7 | |
| 0.11.8 | 2 / 7 | |
| 0.11.7 | 2 / 7 | |
| 0.11.6 | 2 / 7 | |
| 0.11.5 | 2 / 7 | |
| 0.11.4 | 2 / 7 | |
| 0.11.3 | 2 / 7 | |
| 0.11.2 | 2 / 7 | |
| 0.11.1 | 2 / 7 | |
| 0.10.4 | 2 / 7 | |
| 0.10.3 | 2 / 7 | |
| 0.10.1 | 2 / 7 | |
| 0.10.0 | 2 / 7 | |
| 0.9.4 | 1 / 7 | |
| 0.6.1 | 1 / 5 | |
| 0.5.0 | 1 / 5 | |
| 0.4.4 | 1 / 5 | |
| 0.4.3 | 1 / 5 | |
| 0.4.2 | 1 / 5 | |
| 0.4.1 | 1 / 5 | |
| 0.4.0 | 1 / 5 |
v0.11.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: emersonbraun.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: emersonbraun.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.