@apify/actors-mcp-server
Apify MCP Server
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; gitHead absence is a minor metadata gap, not a supply-chain risk for this established package. | ai | |
| source-diff | net-exec-file:dist/web/dist/actor-detail-widget.js | AI (source-diff): Network calls and dynamic require are part of the React widget bundle, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/web/dist/actor-detail-widget.js | AI (source-diff): Standard Vite/React minified widget bundle; React internals clearly visible in sample. | ai | |
| source-diff | obfuscated-file:dist/web/dist/actor-run-widget.js | AI (source-diff): Standard Vite/React minified widget bundle; React internals clearly visible in sample. | ai | |
| source-diff | net-exec-file:dist/web/dist/actor-run-widget.js | AI (source-diff): Network calls and dynamic require are part of the React widget bundle, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/web/dist/search-actors-widget.js | AI (source-diff): Standard Vite/React minified widget bundle; React internals clearly visible in sample. | ai | |
| source-diff | net-exec-file:dist/web/dist/search-actors-widget.js | AI (source-diff): Network calls and dynamic require are part of the React widget bundle, not dropper behavior. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing is confirmed by SLSA provenance attestation; legitimate org-level change for apify. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): axios is a legitimate, established package; phantom-dep fires because it's used in config/indirectly, not a real risk. | ai | |
| phantom-deps | phantom-dep:@types/turndown | AI (phantom-deps): Type-only package used by convention; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:@types/cheerio | AI (phantom-deps): Type-only package used by convention; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): dotenv is a declared runtime dep used via config files, not direct import; stable false positive for this package. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 0.13.0 | 16 / 19 | |
| 0.12.0 | 16 / 19 | |
| 0.11.7 | 16 / 19 | |
| 0.11.6 | 16 / 19 | |
| 0.11.5 | 18 / 19 | |
| 0.11.4 | 18 / 19 | |
| 0.11.3 | 18 / 19 | |
| 0.11.2 | 18 / 19 | |
| 0.11.1 | 18 / 19 | |
| 0.11.0 | 18 / 19 | |
| 0.10.13 | 18 / 19 | |
| 0.10.12 | 17 / 19 | |
| 0.10.11 | 17 / 19 | |
| 0.10.10 | 17 / 19 | |
| 0.10.9 | 17 / 18 | |
| 0.10.8 | 17 / 18 | |
| 0.10.7 | 17 / 18 | |
| 0.7.1 | 18 / 17 |
v0.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.