@blocklet/ai-runtime
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@arcblock/did-connect | AI (dependencies): Same Arcblock org as this package; stable dependency across many versions. | ai | |
| provenance | no-provenance | AI (provenance): Established org package; lack of Sigstore provenance is consistent across all versions and poses no elevated risk here. | ai | |
| dependencies | unvetted-dep:@blocklet/dataset-sdk | AI (dependencies): Same @blocklet org scope; consistent with package's established ecosystem. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Publisher has 198 approved packages and 0 rejections; org-level release cadence explains gaps. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Large multi-export package; phantom-dep heuristic unreliable for bundled/config-referenced deps. | ai | |
| phantom-deps | phantom-dep:express | AI (phantom-deps): Express is a peer/optional server dep referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:node-fetch | AI (phantom-deps): Isomorphic fetch dep referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:json-logic-js | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/express | AI (phantom-deps): Type-only dep; framework-scoped, stable false positive. | ai | |
| phantom-deps | phantom-dep:@blocklet/co-git | AI (phantom-deps): Same-org dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/file-saver | AI (phantom-deps): Type-only dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@blocklet/constant | AI (phantom-deps): Same-org dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-querybuilder | AI (phantom-deps): Declared runtime dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/react-scroll-to-bottom | AI (phantom-deps): Type-only dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/react-syntax-highlighter | AI (phantom-deps): Type-only dep; stable false positive. | ai |
Versions (showing 100 of 262)
| Version | Deps | Published |
|---|---|---|
| 0.4.222 | 62 / 18 | |
| 0.4.221 | 62 / 18 | |
| 0.4.219 | 62 / 18 | |
| 0.4.218 | 62 / 18 | |
| 0.4.217 | 62 / 18 | |
| 0.4.216 | 62 / 18 | |
| 0.4.215 | 62 / 18 | |
| 0.4.214 | 62 / 18 | |
| 0.4.213 | 62 / 18 | |
| 0.4.212 | 62 / 18 | |
| 0.4.211 | 62 / 18 | |
| 0.4.210 | 62 / 18 | |
| 0.4.209 | 62 / 18 | |
| 0.4.208 | 62 / 18 | |
| 0.4.207 | 62 / 18 | |
| 0.4.206 | 62 / 18 | |
| 0.4.205 | 62 / 18 | |
| 0.4.204 | 62 / 18 | |
| 0.4.203 | 62 / 18 | |
| 0.4.202 | 62 / 18 | |
| 0.4.201 | 62 / 18 | |
| 0.4.200 | 62 / 18 | |
| 0.4.199 | 62 / 18 | |
| 0.4.198 | 62 / 18 | |
| 0.4.197 | 62 / 18 | |
| 0.4.196 | 62 / 18 | |
| 0.4.195 | 62 / 18 | |
| 0.4.194 | 62 / 18 | |
| 0.4.193 | 62 / 18 | |
| 0.4.192 | 61 / 18 | |
| 0.4.191 | 61 / 18 | |
| 0.4.190 | 61 / 18 | |
| 0.4.189 | 61 / 18 | |
| 0.4.188 | 61 / 18 | |
| 0.4.187 | 61 / 18 | |
| 0.4.186 | 61 / 18 | |
| 0.4.185 | 61 / 18 | |
| 0.4.184 | 61 / 18 | |
| 0.4.183 | 61 / 18 | |
| 0.4.182 | 61 / 18 | |
| 0.4.177 | 61 / 18 | |
| 0.4.176 | 61 / 18 | |
| 0.4.174 | 61 / 18 | |
| 0.4.173 | 61 / 18 | |
| 0.4.172 | 61 / 18 | |
| 0.4.171 | 61 / 18 | |
| 0.4.170 | 61 / 18 | |
| 0.4.169 | 61 / 18 | |
| 0.4.167 | 61 / 18 | |
| 0.4.166 | 61 / 18 | |
| 0.4.165 | 61 / 18 | |
| 0.4.164 | 61 / 18 | |
| 0.4.163 | 61 / 18 | |
| 0.4.162 | 61 / 18 | |
| 0.4.161 | 61 / 18 | |
| 0.4.160 | 61 / 18 | |
| 0.4.159 | 61 / 18 | |
| 0.4.158 | 61 / 18 | |
| 0.4.157 | 61 / 18 | |
| 0.4.156 | 61 / 18 | |
| 0.4.155 | 61 / 18 | |
| 0.4.154 | 61 / 18 | |
| 0.4.153 | 61 / 18 | |
| 0.4.152 | 61 / 18 | |
| 0.4.151 | 61 / 18 | |
| 0.4.150 | 61 / 18 | |
| 0.4.149 | 61 / 18 | |
| 0.4.148 | 61 / 18 | |
| 0.4.147 | 61 / 18 | |
| 0.4.146 | 61 / 18 | |
| 0.4.145 | 61 / 18 | |
| 0.4.144 | 61 / 18 | |
| 0.4.143 | 61 / 18 | |
| 0.4.142 | 61 / 18 | |
| 0.4.141 | 61 / 18 | |
| 0.4.140 | 61 / 18 | |
| 0.4.139 | 61 / 18 | |
| 0.4.138 | 61 / 18 | |
| 0.4.137 | 61 / 18 | |
| 0.4.136 | 61 / 18 | |
| 0.4.135 | 61 / 18 | |
| 0.4.134 | 61 / 18 | |
| 0.4.133 | 61 / 18 | |
| 0.4.132 | 61 / 18 | |
| 0.4.131 | 61 / 18 | |
| 0.4.130 | 61 / 18 | |
| 0.4.129 | 61 / 18 | |
| 0.4.122 | 59 / 17 | |
| 0.4.121 | 59 / 17 | |
| 0.4.120 | 59 / 17 | |
| 0.4.119 | 59 / 17 | |
| 0.4.118 | 59 / 17 | |
| 0.4.117 | 55 / 17 | |
| 0.4.116 | 55 / 17 | |
| 0.4.115 | 55 / 17 | |
| 0.4.114 | 55 / 17 | |
| 0.4.113 | 55 / 17 | |
| 0.4.112 | 55 / 17 | |
| 0.4.111 | 55 / 17 | |
| 0.4.110 | 55 / 17 |
v0.4.222
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.221
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.219
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.218
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.217
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.216
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.215
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.214
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.213
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.212
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.211
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.210
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.209
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.208
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.207
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.206
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.205
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.204
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.203
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.202
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.201
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.200
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.199
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.198
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.197
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.196
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.195
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.194
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.193
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.192
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.191
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.190
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.189
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.188
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.187
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.186
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.185
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.184
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.183
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.182
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.177
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.176
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.174
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.173
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.172
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.171
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.170
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.169
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.167
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.166
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.165
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.164
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.163
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.162
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.161
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.160
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.159
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.158
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.157
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.156
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.155
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.154
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.153
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.152
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.151
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.150
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.149
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.148
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.147
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.146
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.145
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.144
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.143
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.142
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.141
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.140
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.139
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.138
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.137
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.136
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.135
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.134
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.133
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.132
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.131
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.130
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.129
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.122
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.121
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.120
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.119
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.118
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.117
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.116
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.115
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.114
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.113
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.112
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.111
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.110
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.