← Home

@bastani/atomic

Configuration management CLI and SDK for coding agents

100
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

bastani

Keywords

coding-agentaillmclituiagent

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@dbos-inc/dbos-sdk AI (phantom-deps): Established SDK dep, large refactor likely moved usage out of scanned scope. ai
phantom-deps phantom-dep:embedded-postgres AI (phantom-deps): Established DB dep likely used via native binary invocation, not JS import. ai
phantom-deps phantom-dep:tsx AI (phantom-deps): Build-time dependency referenced in scripts; not a runtime concern for this package. ai
source-diff large-new-source-files AI (source-diff): Expected growth from bundling/build output across a large monorepo package. ai
publish-pattern new-deps-added AI (publish-pattern): semver is a widely-used, benign utility library; low risk addition. ai
npm-metadata bundled-binaries AI (npm-metadata): pi-tui native prebuilds for darwin/win32; expected for TUI binding. ai
phantom-deps phantom-dep:@bastani/mcp AI (phantom-deps): Same-org runtime sibling, loaded dynamically. ai
dependencies unvetted-dep:@bastani/web-access AI (dependencies): workspace:* sibling in own monorepo. ai
dependencies unvetted-dep:@bastani/mcp AI (dependencies): workspace:* sibling in own monorepo. ai
dependencies unvetted-dep:@bastani/intercom AI (dependencies): workspace:* sibling in own monorepo. ai
dependencies unvetted-dep:@bastani/subagents AI (dependencies): workspace:* sibling in own monorepo. ai
dependencies unvetted-dep:@bastani/workflows AI (dependencies): workspace:* sibling in own monorepo. ai
dependencies unvetted-dep:@bastani/atomic-natives AI (dependencies): First-party sibling package in same org/monorepo. ai
phantom-deps phantom-dep:@bastani/atomic-natives AI (phantom-deps): Same-org native binding dep, not directly imported by design. ai
semgrep semgrep:silent-process-exec-var AI (semgrep): Same live-server daemonization pattern; benign for this package. ai
semgrep semgrep:toplevel-fetch AI (semgrep): Fetches localhost stop endpoint to shut down dev server; not exfiltration. ai
semgrep semgrep:silent-process-exec AI (semgrep): Daemonizes itself via --background flag; standard dev-server self-restart pattern, not malicious. ai
source-diff obfuscated-file:dist/builtin/cursor/src/proto/agent_pb.ts AI (source-diff): File is protoc-gen-es generated TypeScript with base64 proto descriptor; not obfuscation. ai
source-diff obfuscated-file:dist/modes/interactive/components/daxnuts.js AI (source-diff): Hex-encoded RGB pixel data for an easter-egg image render, not executable steganography. ai
semgrep semgrep:new-function-constructor AI (semgrep): Used to load DOOM JS module in examples/; not in production code path. ai
semgrep semgrep:child-process-import AI (semgrep): Windows toast notification helper in examples/; expected use of child_process. ai
source-diff obfuscated-file:dist/builtin/mcp/app-bridge.bundle.js AI (source-diff): Standard minified bundle of MCP SDK and zod; not obfuscated malware. ai
semgrep semgrep:steganography-image-eval AI (semgrep): DOOM WAD file loader in examples/ directory; not production code path. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Localhost OAuth callback URI (127.0.0.1:8080) in example extension; benign. ai
source-diff obfuscated-file:dist/services/config/additional-instructions.d.ts AI (source-diff): Long line is a readable Markdown string literal for AI agent instructions, not obfuscated code. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall selects platform-specific prebuilt binary from optional deps — standard native binary distribution pattern. ai
source-diff source-size-dropped AI (source-diff): Source shrinkage reflects intentional refactor to platform-specific binary packages, not malicious stubbing. ai
phantom-deps phantom-dep:commander AI (phantom-deps): commander is a declared dependency; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): yaml is a declared dependency; phantom-dep heuristic false positive for this package. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode in orchestrator-entry is a documented deserialization pattern, not payload hiding. ai
semgrep semgrep:env-spread AI (semgrep): Spreading process.env into child_process spawn options is standard CLI practice; not exfiltration. ai

Versions (showing 100 of 101)

Version Deps Published
0.9.10 34 / 11
0.9.7 32 / 11
0.9.5 32 / 11
0.9.4 31 / 11
0.9.3 30 / 11
0.9.2 29 / 11
0.9.1 29 / 11
0.9.0 29 / 11
0.8.30 29 / 11
0.8.29 28 / 10
0.8.28 26 / 10
0.8.27 26 / 10
0.8.26 27 / 11
0.8.25 28 / 10
0.8.24 28 / 10
0.8.23 26 / 10
0.8.22 26 / 10
0.8.21 26 / 10
0.8.20 26 / 10
0.8.19 26 / 10
0.8.18 26 / 10
0.8.17 26 / 10
0.8.16 26 / 10
0.8.15 26 / 10
0.8.14 26 / 10
0.8.13 26 / 10
0.8.12 26 / 10
0.8.11 25 / 9
0.8.10 25 / 9
0.8.9 25 / 9
0.8.8 25 / 9
0.8.7 25 / 9
0.8.6 25 / 9
0.8.5 25 / 9
0.8.4 25 / 9
0.8.3 25 / 9
0.8.2 25 / 9
0.8.1 25 / 9
0.8.0 21 / 9
0.7.17 0 / 0
0.7.16 0 / 0
0.7.15 0 / 0
0.7.14 0 / 0
0.7.13 0 / 0
0.7.12 0 / 0
0.7.11 0 / 0
0.7.10 0 / 0
0.7.9 0 / 0
0.7.8 0 / 0
0.7.7 0 / 0
0.7.6 0 / 0
0.7.5 0 / 0
0.7.4 0 / 0
0.7.3 0 / 0
0.7.2 0 / 0
0.7.1 0 / 0
0.7.0 0 / 0
0.6.8 14 / 6
0.6.7 14 / 6
0.6.6 13 / 6
0.6.5 13 / 6
0.6.4 13 / 6
0.6.3 11 / 6
0.6.2 11 / 6
0.6.1 11 / 6
0.6.0 11 / 6
0.5.34 11 / 6
0.5.33 11 / 6
0.5.32 11 / 6
0.5.31 11 / 6
0.5.30 11 / 6
0.5.29 11 / 6
0.5.28 11 / 6
0.5.27 11 / 6
0.5.26 11 / 6
0.5.25 11 / 6
0.5.24 11 / 6
0.5.23 11 / 6
0.5.22 11 / 6
0.5.21 11 / 6
0.5.20 11 / 6
0.5.19 11 / 6
0.5.18 11 / 6
0.5.17 11 / 6
0.5.16 11 / 6
0.5.15 11 / 6
0.5.14 11 / 6
0.5.13 12 / 6
0.5.12 12 / 6
0.5.11 12 / 6
0.5.10 12 / 6
0.5.9 12 / 6
0.5.8 12 / 6
0.5.7 12 / 6
0.5.6 12 / 6
0.5.5 12 / 6
0.5.4 12 / 6
0.5.3 12 / 6
0.5.2 12 / 6
0.5.1 12 / 6
Showing 100 of 101 Next page →

v0.9.10

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.