← Home

@botpress/zai

10
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

slvnperronbotpress-cloud-opsfranklevasseurmichael.massonpaul.chevilleydavid-ferland

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get() in e2e test proxy utility; not obfuscation. ai
typosquat typosquat.levenshtein:hapi AI (typosquat): Scoped @botpress package; Levenshtein match to 'hapi' is coincidental, not impersonation. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @botpress package; Levenshtein match to 'joi' is coincidental, not impersonation. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Scoped @botpress package; Levenshtein match to 'zod' is coincidental, not impersonation. ai

Versions (showing 10 of 10)

Version Deps Published
2.6.24 5 / 15
2.6.23 5 / 15
2.6.22 5 / 14
2.6.21 5 / 14
2.6.20 5 / 14
2.6.19 5 / 14
2.0.8 4 / 9
2.0.7 4 / 9
2.0.6 4 / 9
2.0.5 4 / 9

v2.6.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.6.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.6.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.6.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.6.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.6.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.