← Home

@ax-llm/ax-tools

Ax tools package

51
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

dosco

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:postinstall AI (install-scripts): Runs a local bundled script, not a remote fetch; SLSA provenance confirms CI/CD publish integrity. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation mitigates account-takeover concern from dormancy gap. ai
email-domain unclaimed-email:https://twitter.com/dosco AI (email-domain): Author field contains a Twitter URL, not an email address; domain check is a false positive. ai
semgrep semgrep:env-spread AI (semgrep): LLM tools package; env-spread in bundled CJS output is expected for subprocess/MCP communication patterns. ai
semgrep semgrep:child-process-import AI (semgrep): Package spawns child processes for tool execution (stdio MCP pattern); child_process use is intentional and documented. ai

Versions (showing 51 of 157)

View all versions
Version Deps Published
23.0.5 2 / 0
23.0.4 2 / 0
23.0.3 2 / 0
23.0.2 2 / 0
23.0.1 1 / 0
23.0.0 1 / 0
22.0.9 1 / 0
22.0.8 1 / 0
22.0.7 1 / 0
22.0.6 1 / 0
22.0.5 1 / 0
22.0.4 1 / 0
22.0.3 1 / 0
22.0.2 1 / 0
22.0.1 1 / 0
22.0.0 1 / 0
21.0.14 1 / 0
21.0.13 1 / 0
21.0.12 1 / 0
21.0.11 1 / 0
21.0.10 1 / 0
21.0.9 1 / 0
21.0.8 1 / 0
21.0.7 1 / 0
21.0.6 1 / 0
21.0.5 1 / 0
21.0.4 1 / 0
21.0.3 1 / 0
21.0.2 1 / 0
21.0.1 1 / 0
21.0.0 1 / 0
20.0.2 1 / 0
20.0.1 1 / 0
20.0.0 1 / 0
19.0.45 1 / 0
19.0.44 1 / 0
19.0.43 1 / 0
19.0.42 1 / 0
19.0.41 1 / 0
19.0.40 1 / 0
19.0.39 1 / 0
19.0.38 1 / 0
19.0.37 1 / 0
19.0.36 1 / 0
19.0.35 1 / 0
19.0.34 1 / 0
19.0.33 1 / 0
19.0.32 1 / 0
19.0.31 1 / 0
19.0.30 1 / 0
19.0.29 1 / 0

v23.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v23.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v23.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v23.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v23.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v23.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.