← Home

@coinbase/agentkit

24
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

coinbase-ownercoinbase-npm

Keywords

coinbasesdkcryptocdpagentkitaiagentnodejstypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Org-managed publisher with strong track record; maintainer churn is expected, not a takeover indicator. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are well-known crypto/SDK libs matching AgentKit's stated functionality. ai
phantom-deps phantom-dep:x402 AI (phantom-deps): x402 is a declared payment protocol dep used in config/integration; phantom detection is a false positive for this package. ai
dependencies unvetted-dep:x402-axios AI (dependencies): x402-axios is a Coinbase-ecosystem payment protocol library; its use here is consistent with AgentKit's purpose. ai
dependencies unvetted-dep:@coinbase/x402 AI (dependencies): Same Coinbase org; payment protocol SDK consistent with agentkit. ai
dependencies unvetted-dep:@vaultsfyi/sdk AI (dependencies): DeFi vaults SDK; consistent with agentkit's DeFi integration scope. ai
dependencies unvetted-dep:@zerodev/intent AI (dependencies): Account abstraction SDK; consistent with agentkit's wallet/intent scope. ai
dependencies unvetted-dep:@ensofinance/sdk AI (dependencies): DeFi routing SDK; consistent with agentkit's DeFi integration scope. ai
dependencies unvetted-dep:@zoralabs/coins-sdk AI (dependencies): Known Zora NFT/coins SDK; consistent with agentkit's scope. ai
dependencies unvetted-dep:clanker-sdk AI (dependencies): DeFi token deployment SDK; consistent with agentkit's scope. ai
dependencies unvetted-dep:@coinbase/coinbase-sdk AI (dependencies): Core Coinbase SDK from same org; expected dependency. ai
phantom-deps phantom-dep:@coinbase/x402 AI (phantom-deps): Same org scope; likely re-exported or used indirectly in action providers. ai
phantom-deps phantom-dep:@privy-io/public-api AI (phantom-deps): Referenced in config/type files; stable false positive for this package. ai
phantom-deps phantom-dep:@zoralabs/protocol-deployments AI (phantom-deps): Referenced in config files; stable false positive for this package. ai
dependencies unvetted-dep:sushi AI (dependencies): Known DeFi SDK; consistent with agentkit's DeFi integration scope. ai
dependencies unvetted-dep:@privy-io/server-auth AI (dependencies): Known Privy auth SDK; consistent with agentkit's wallet/auth scope. ai

Versions (showing 24 of 24)

Version Deps Published
0.10.4 35 / 18
0.10.3 32 / 18
0.10.2 30 / 18
0.10.1 28 / 18
0.10.0 26 / 18
0.9.1 26 / 18
0.9.0 25 / 18
0.8.2 24 / 18
0.8.1 22 / 18
0.8.0 22 / 18
0.7.2 22 / 18
0.7.1 22 / 18
0.7.0 22 / 18
0.6.0 17 / 18
0.5.0 17 / 17
0.4.0 12 / 16
0.3.0 12 / 16
0.2.3 10 / 8
0.2.2 10 / 8
0.2.1 9 / 8
0.2.0 9 / 8
0.1.2 6 / 8
0.1.1 6 / 8
0.1.0 6 / 8

v0.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: coinbase-npm.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: coinbase-npm.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.2

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: cb-clintonreece → coinbase-owner (on 2025-02-08, now via trusted publisher with provenance) provenance

This version was published by a different npm account (coinbase-owner) than the most recent previously approved version (cb-clintonreece) on 2025-02-08, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.