← Home

@contractspec/example.policy-safe-knowledge-assistant

All-in-one template example: policy-safe knowledge assistant with locale/jurisdiction gating, versioned KB snapshots, HITL update pipeline, and learning hub.

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

farzim

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@contractspec/module.notifications AI (phantom-deps): Same-org scoped; likely re-exported or transitively used by other deps. ai
phantom-deps phantom-dep:@contractspec/lib.schema AI (phantom-deps): Same-org scoped; likely re-exported or transitively used by other deps. ai
phantom-deps phantom-dep:@contractspec/lib.metering AI (phantom-deps): Same-org scoped; likely re-exported or transitively used by other deps. ai
phantom-deps phantom-dep:@contractspec/lib.feature-flags AI (phantom-deps): Same-org scoped; likely re-exported or transitively used by other deps. ai
phantom-deps phantom-dep:@contractspec/lib.identity-rbac AI (phantom-deps): Same-org scoped; likely re-exported or transitively used by other deps. ai
phantom-deps phantom-dep:@contractspec/module.audit-trail AI (phantom-deps): Same-org scoped; likely re-exported or transitively used by other deps. ai
phantom-deps phantom-dep:@contractspec/lib.jobs AI (phantom-deps): Same-org scoped; likely re-exported or transitively used by other deps. ai
phantom-deps phantom-dep:@contractspec/lib.files AI (phantom-deps): Same-org scoped; likely re-exported or transitively used by other deps. ai
phantom-deps phantom-dep:@contractspec/module.learning-journey AI (phantom-deps): Same-org dep likely referenced via config/re-export; stable false positive for this monorepo package. ai
phantom-deps phantom-dep:@contractspec/example.learning-patterns AI (phantom-deps): Same-org dep; stable false positive for this monorepo package. ai
phantom-deps phantom-dep:@contractspec/example.kb-update-pipeline AI (phantom-deps): Same-org dep; stable false positive for this monorepo package. ai
phantom-deps phantom-dep:@contractspec/example.versioned-knowledge-base AI (phantom-deps): Same-org dep; stable false positive for this monorepo package. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom declared as runtime dep and used in UI components; phantom-dep heuristic false positive for this package. ai

Versions (showing 51 of 84)

View all versions
Version Deps Published
3.7.33 12 / 5
3.7.32 12 / 5
3.7.31 12 / 5
3.7.30 12 / 5
3.7.29 12 / 5
3.7.28 12 / 5
3.7.27 12 / 5
3.7.26 12 / 5
3.7.25 12 / 5
3.7.24 12 / 5
3.7.23 12 / 5
3.7.22 12 / 5
3.7.20 12 / 5
3.7.19 12 / 5
3.7.18 12 / 5
3.7.17 12 / 5
3.7.16 12 / 5
3.7.15 12 / 5
3.7.14 12 / 5
3.7.12 12 / 5
3.7.10 12 / 5
3.7.7 12 / 5
3.7.6 12 / 5
3.7.5 12 / 5
3.7.4 12 / 5
3.7.3 12 / 5
3.7.1 12 / 5
3.7.0 12 / 5
3.6.0 12 / 5
3.5.5 12 / 5
3.5.4 12 / 5
3.5.3 12 / 5
3.5.2 12 / 5
3.5.0 12 / 5
3.4.3 12 / 5
3.4.2 12 / 5
3.4.1 12 / 5
3.4.0 12 / 5
3.3.0 12 / 5
3.2.0 12 / 5
3.1.1 12 / 5
3.0.0 12 / 5
2.9.1 12 / 5
2.9.0 12 / 5
2.8.0 12 / 5
2.7.0 12 / 5
2.6.1 12 / 5
2.6.0 12 / 5
2.5.0 12 / 5
2.4.0 12 / 5
2.3.0 12 / 5

v3.7.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.