@agentuity/frontend
51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
huijirop0tofpiejhaynie
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): p0tofpie is an established publisher (1439 approved) within the Agentuity org; transition appears legitimate. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Same rationale — p0tofpie is a trusted org publisher, not an unknown actor. | ai | |
| source-diff | obfuscated-file:dist/beacon.js | AI (source-diff): Same beacon script in different form; readable analytics code, not obfuscated malware. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are beacon build artifacts; consistent with documented build script adding beacon feature. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by addition of minified beacon scripts; legitimate feature addition. | ai | |
| source-diff | obfuscated-file:dist/beacon-script.js | AI (source-diff): Labeled minified analytics beacon; code is readable standard browser telemetry, not obfuscated malware. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal monorepo package; missing metadata is cosmetic, not indicative of spam/malware. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across versions of this internal org package; not a risk signal. | ai |
Versions (showing 51 of 155)
| Version | Deps | Published |
|---|---|---|
| 2.0.30 | 1 / 4 | |
| 2.0.29 | 1 / 4 | |
| 2.0.28 | 1 / 4 | |
| 2.0.27 | 1 / 4 | |
| 2.0.26 | 1 / 4 | |
| 2.0.25 | 1 / 4 | |
| 2.0.24 | 1 / 4 | |
| 2.0.23 | 1 / 4 | |
| 2.0.22 | 1 / 4 | |
| 2.0.21 | 1 / 4 | |
| 2.0.20 | 1 / 4 | |
| 2.0.19 | 1 / 4 | |
| 2.0.18 | 1 / 4 | |
| 2.0.17 | 1 / 4 | |
| 2.0.16 | 1 / 4 | |
| 2.0.15 | 1 / 4 | |
| 2.0.14 | 1 / 4 | |
| 2.0.13 | 1 / 4 | |
| 2.0.12 | 1 / 4 | |
| 2.0.11 | 1 / 4 | |
| 2.0.10 | 1 / 4 | |
| 2.0.9 | 1 / 4 | |
| 2.0.8 | 1 / 4 | |
| 2.0.7 | 1 / 4 | |
| 2.0.6 | 1 / 4 | |
| 2.0.5 | 1 / 4 | |
| 2.0.4 | 1 / 4 | |
| 2.0.3 | 1 / 4 | |
| 2.0.2 | 1 / 4 | |
| 2.0.1 | 1 / 4 | |
| 2.0.0 | 1 / 4 | |
| 1.0.64 | 1 / 4 | |
| 1.0.63 | 1 / 4 | |
| 1.0.62 | 1 / 4 | |
| 1.0.61 | 1 / 4 | |
| 1.0.60 | 1 / 4 | |
| 1.0.59 | 1 / 4 | |
| 1.0.58 | 1 / 4 | |
| 1.0.57 | 1 / 4 | |
| 1.0.56 | 1 / 4 | |
| 1.0.55 | 1 / 4 | |
| 1.0.54 | 1 / 4 | |
| 1.0.53 | 1 / 4 | |
| 1.0.52 | 1 / 4 | |
| 1.0.51 | 1 / 4 | |
| 1.0.50 | 1 / 4 | |
| 1.0.49 | 1 / 4 | |
| 1.0.48 | 1 / 4 | |
| 1.0.47 | 1 / 4 | |
| 1.0.46 | 1 / 4 | |
| 1.0.45 | 1 / 4 |
v2.0.30
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.