← Home

@agentworkforce/runtime

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

khaliqgantwillwashburn

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@relayfile/relay-helpers AI (dependencies): Sibling package in same relayfile scope already used elsewhere; no malicious behavior evidenced. ai
dependencies unvetted-dep:@agentworkforce/events AI (dependencies): Same-org monorepo sibling pinned to identical version; not a third-party unvetted dep. ai
publish-pattern new-deps-added AI (publish-pattern): Internal sibling package split, consistent with monorepo versioning. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Monorepo initial publish pattern; publisher has strong track record. ai
npm-metadata no-description AI (npm-metadata): Monorepo package; missing description is cosmetic, not a risk signal here. ai
phantom-deps phantom-dep:@agent-assistant/proactive AI (phantom-deps): Dependency is used via a subpath export (./proactive); not directly imported in main entry but legitimately declared. ai

Versions (showing 51 of 92)

View all versions
Version Deps Published
4.1.34 7 / 0
4.1.33 7 / 0
4.1.32 7 / 0
4.1.31 7 / 0
4.1.30 7 / 0
4.1.29 7 / 0
4.1.28 7 / 0
4.1.27 7 / 0
4.1.26 7 / 0
4.1.25 7 / 0
4.1.24 7 / 0
4.1.23 7 / 0
4.1.22 6 / 0
4.1.21 6 / 0
4.1.20 6 / 0
4.1.19 6 / 0
4.1.18 5 / 0
4.1.17 5 / 0
4.1.16 5 / 0
4.1.15 5 / 0
4.1.14 5 / 0
4.1.13 5 / 0
4.1.12 5 / 0
4.1.11 5 / 0
4.1.10 5 / 0
4.1.9 5 / 0
4.1.8 5 / 0
4.1.7 5 / 0
4.1.6 5 / 0
4.1.5 5 / 0
4.1.4 5 / 0
4.1.3 5 / 0
4.1.2 5 / 0
4.1.1 5 / 0
4.1.0 5 / 0
4.0.6 5 / 0
4.0.5 5 / 0
4.0.4 5 / 0
4.0.3 5 / 0
4.0.2 5 / 0
4.0.1 5 / 0
4.0.0 5 / 0
3.0.52 4 / 0
3.0.51 4 / 0
3.0.50 3 / 0
3.0.49 3 / 0
3.0.47 3 / 0
3.0.46 3 / 0
3.0.45 3 / 0
3.0.44 3 / 0
3.0.43 3 / 0

v4.1.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.