@botpress/runtime
Lightweight runtime library for ADK-based Botpress agents
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@botpress/evals | AI (dependencies): First-party @botpress org package; unvetted only because it's newly published alongside this version. | ai | |
| phantom-deps | phantom-dep:@botpress/chat | AI (phantom-deps): Same-org dep; phantom detection is a false positive for this package's module structure. | ai | |
| phantom-deps | phantom-dep:@botpress/evals | AI (phantom-deps): Same-org dep; phantom detection is a false positive for this package's module structure. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-logs | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-logs-otlp-http | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-trace-node | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@bpinternal/const | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/semantic-conventions | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-trace-otlp-http | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation-http | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/core | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:fast-safe-stringify | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@bpinternal/thicktoken | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/resources | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:undici | AI (phantom-deps): Known implicit runtime dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:p-limit | AI (phantom-deps): Bundled output pattern; stable false positive. | ai | |
| dependencies | unvetted-dep:llmz | AI (dependencies): Botpress-ecosystem dep; consistent with package purpose. | ai | |
| phantom-deps | phantom-dep:object-sizeof | AI (phantom-deps): Bundled output pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:fast-xml-parser | AI (phantom-deps): Bundled output pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:pretty-bytes | AI (phantom-deps): Bundled output pattern; stable false positive. | ai | |
| dependencies | unvetted-dep:@botpress/sdk | AI (dependencies): First-party Botpress SDK; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@botpress/zai | AI (dependencies): First-party Botpress dep; stable false positive. | ai | |
| dependencies | unvetted-dep:@bpinternal/zui | AI (dependencies): First-party Botpress internal dep; stable false positive. | ai | |
| dependencies | unvetted-dep:@botpress/client | AI (dependencies): First-party Botpress client; stable false positive. | ai | |
| dependencies | unvetted-dep:@bpinternal/const | AI (dependencies): First-party Botpress internal dep; stable false positive. | ai | |
| dependencies | unvetted-dep:@botpress/cognitive | AI (dependencies): First-party Botpress dep; stable false positive. | ai | |
| dependencies | unvetted-dep:@bpinternal/thicktoken | AI (dependencies): First-party Botpress internal dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:ms | AI (phantom-deps): Bundled output pattern; phantom-dep heuristic fires on bundled packages. | ai | |
| phantom-deps | phantom-dep:glob | AI (phantom-deps): Bundled output pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:ulid | AI (phantom-deps): Bundled output pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Bundled output pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:bytes | AI (phantom-deps): Bundled output pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:dedent | AI (phantom-deps): Bundled output pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Bundled output pattern; stable false positive. | ai |
Versions (showing 8 of 108)
| Version | Deps | Published |
|---|---|---|
| 1.3.20 | 29 / 9 | |
| 1.3.19 | 29 / 9 | |
| 1.3.18 | 29 / 9 | |
| 1.3.17 | 29 / 9 | |
| 1.3.16 | 29 / 9 | |
| 1.3.15 | 29 / 9 | |
| 1.3.14 | 29 / 9 | |
| 1.3.13 | 29 / 9 |
v1.3.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.