← Home

@copilotkit/react-core

41
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

copilotkit

Keywords

aiassistantautomationcopilotcopilotkitjavascriptnextjsnodejsreacttanstack-intenttextarea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/copilotkit-DqDT5RLa.d.mts AI (source-diff): Bundled .d.mts type declarations with long lines; not obfuscated code. ai
source-diff obfuscated-file:dist/copilotkit-Ctvinul7.d.cts AI (source-diff): Bundled .d.cts type declarations with long lines; not obfuscated code. ai
source-diff obfuscated-file:dist/copilotkit-D42EuTt0.d.mts AI (source-diff): Bundled .d.mts type declaration file with long lines; not obfuscated. ai
source-diff obfuscated-file:dist/copilotkit-CtqalfG8.d.cts AI (source-diff): Bundled .d.cts type declaration file with long lines; not obfuscated. ai
source-diff obfuscated-file:dist/copilotkit-D16eCFkt.d.cts AI (source-diff): TypeScript declaration file with long type lines; standard bundler output, not obfuscation. ai
source-diff obfuscated-file:dist/copilotkit-CEJz6krE.d.mts AI (source-diff): TypeScript declaration file with long type lines; standard bundler output, not obfuscation. ai
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions CI/CD with SLSA attestation; expected for this org. ai
source-diff obfuscated-file:dist/copilotkit-BN4I_y1n.d.mts AI (source-diff): TypeScript declaration file with long type lines; standard bundler output, not obfuscation. ai
source-diff obfuscated-file:dist/copilotkit-sQWiKtxA.d.cts AI (source-diff): TypeScript declaration file with long type lines; standard bundler output, not obfuscation. ai
source-diff obfuscated-file:dist/copilotkit-WlmeVijs.d.mts AI (source-diff): Bundled .d.mts type declaration file with long lines; not obfuscation. ai
source-diff obfuscated-file:dist/copilotkit-BK9CVq9A.d.cts AI (source-diff): Bundled .d.cts type declaration file with long lines; not obfuscation. ai
source-diff obfuscated-file:dist/copilotkit-Dg4r4Gi_.d.cts AI (source-diff): TypeScript .d.cts declaration file with long type-export lines; standard bundler output, not obfuscation. ai
source-diff obfuscated-file:dist/copilotkit-DFaI4j2r.d.mts AI (source-diff): TypeScript .d.mts declaration file with long type-export lines; standard bundler output. ai
source-diff obfuscated-file:dist/v2/index.d.cts AI (source-diff): Barrel re-export declaration file; long lines from many named exports, not obfuscation. ai
source-diff obfuscated-file:dist/v2/index.d.mts AI (source-diff): Barrel re-export declaration file; long lines from many named exports, not obfuscation. ai
source-diff obfuscated-file:dist/copilotkit-Dv8zU8_U.d.cts AI (source-diff): TypeScript declaration bundle with long type lines; not obfuscated code. ai
source-diff obfuscated-file:dist/copilotkit-f2Uq0RwG.d.mts AI (source-diff): TypeScript declaration bundle with long type lines; not obfuscated code. ai
source-diff obfuscated-file:dist/copilotkit-CCbxm6JM.d.mts AI (source-diff): TypeScript declaration bundle with long type lines; not obfuscated code. ai
source-diff obfuscated-file:dist/copilotkit-BtP7w7cT.d.cts AI (source-diff): TypeScript declaration bundle with long type lines; not obfuscated code. ai
source-diff obfuscated-file:dist/copilotkit-dwDWYpya.d.cts AI (source-diff): TypeScript declaration bundle with long type lines; standard build output, not obfuscation. ai
source-diff obfuscated-file:dist/copilotkit-BuhSUZHb.d.mts AI (source-diff): TypeScript declaration bundle with long type lines; standard build output, not obfuscation. ai
source-diff obfuscated-file:dist/components/dev-console/developer-console-modal.js AI (source-diff): Standard tsup/esbuild CJS bundle output, not obfuscation; stable for this package. ai
source-diff obfuscated-file:dist/components/dev-console/icons.js AI (source-diff): SVG icon components bundled via tsup; long lines from inline SVG paths. ai
source-diff obfuscated-file:dist/components/dev-console/console-trigger.js AI (source-diff): Standard tsup/esbuild CJS bundle output, not obfuscation; stable for this package. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get used for a standard thenable/Promise check — not obfuscation; stable pattern for this package. ai
phantom-deps phantom-dep:@scarf/scarf AI (phantom-deps): scarf is a declared dep used via config; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:rxjs AI (phantom-deps): rxjs is a declared runtime dep used in build/config context; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:untruncate-json AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:tw-animate-css AI (phantom-deps): CSS-only dep referenced in config; phantom-dep heuristic false positive. ai

Versions (showing 41 of 41)

Version Deps Published
1.59.5 26 / 28
1.59.4 26 / 28
1.59.3 26 / 28
1.59.2 26 / 28
1.59.1 26 / 27
1.59.0 26 / 27
1.58.0 26 / 27
1.57.4 26 / 27
1.57.3 26 / 26
1.57.2 26 / 26
1.57.1 26 / 26
1.57.0 26 / 26
1.56.5 26 / 26
1.56.4 26 / 26
1.56.3 26 / 26
1.56.2 26 / 26
1.56.1 26 / 26
1.56.0 26 / 26
1.55.3 26 / 26
1.55.2 26 / 26
1.55.1 26 / 26
1.55.0 26 / 26
1.54.1 8 / 15
1.54.0 8 / 15
1.53.0 8 / 15
1.52.1 8 / 15
1.52.0 8 / 15
1.51.2 8 / 17
1.51.1 3 / 21
1.51.0 3 / 21
1.50.1 8 / 17
1.50.0 8 / 17
1.9.3 5 / 15
1.9.2 5 / 15
1.9.1 5 / 11
1.9.0 5 / 11
1.8.14 5 / 11
1.8.13 5 / 11
1.8.12 5 / 11
1.8.11 5 / 11
1.8.10 5 / 11

v1.59.5

3 findings
HIGH New obfuscated file: dist/copilotkit-Ctvinul7.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-DqDT5RLa.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.59.4

3 findings
HIGH New obfuscated file: dist/copilotkit-CtqalfG8.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-D42EuTt0.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.59.3

3 findings
HIGH New obfuscated file: dist/copilotkit-D16eCFkt.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-CEJz6krE.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.59.2

3 findings
HIGH New obfuscated file: dist/copilotkit-D16eCFkt.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-CEJz6krE.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.59.1

4 findings
HIGH Publisher changed: copilotkit → GitHub Actions (on 2026-05-29) provenance

This version was published by a different npm account than previous versions on 2026-05-29. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/copilotkit-BK9CVq9A.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-WlmeVijs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.59.0

4 findings
HIGH Publisher changed: copilotkit → GitHub Actions (on 2026-05-29) provenance

This version was published by a different npm account than previous versions on 2026-05-29. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/copilotkit-BK9CVq9A.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-WlmeVijs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.58.0

4 findings
HIGH Publisher changed: copilotkit → GitHub Actions (on 2026-05-26) provenance

This version was published by a different npm account than previous versions on 2026-05-26. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/copilotkit-BK9CVq9A.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-WlmeVijs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.57.4

4 findings
HIGH Publisher changed: copilotkit → GitHub Actions (on 2026-05-21) provenance

This version was published by a different npm account than previous versions on 2026-05-21. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/copilotkit-BK9CVq9A.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-WlmeVijs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.57.3

3 findings
HIGH New obfuscated file: dist/copilotkit-BK9CVq9A.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-WlmeVijs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.57.2

3 findings
HIGH New obfuscated file: dist/copilotkit-BK9CVq9A.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-WlmeVijs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.57.1

3 findings
HIGH New obfuscated file: dist/copilotkit-sQWiKtxA.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-BN4I_y1n.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.57.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.56.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.56.3

5 findings
HIGH New obfuscated file: dist/copilotkit-Dg4r4Gi_.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/v2/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-DFaI4j2r.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/v2/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.56.2

3 findings
HIGH New obfuscated file: dist/copilotkit-BtP7w7cT.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-CCbxm6JM.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.56.1

3 findings
HIGH New obfuscated file: dist/copilotkit-BtP7w7cT.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-CCbxm6JM.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.56.0

3 findings
HIGH New obfuscated file: dist/copilotkit-Dv8zU8_U.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-f2Uq0RwG.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.55.3

3 findings
HIGH New obfuscated file: dist/copilotkit-dwDWYpya.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-BuhSUZHb.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.55.2

3 findings
HIGH New obfuscated file: dist/copilotkit-dwDWYpya.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-BuhSUZHb.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.55.1

3 findings
HIGH New obfuscated file: dist/copilotkit-dwDWYpya.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-BuhSUZHb.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.55.0

3 findings
HIGH New obfuscated file: dist/copilotkit-dwDWYpya.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/copilotkit-BuhSUZHb.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.54.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.54.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.53.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.52.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.52.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.51.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.51.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.51.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.50.1

4 findings
HIGH New obfuscated file: dist/components/dev-console/console-trigger.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/dev-console/developer-console-modal.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/dev-console/icons.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.50.0

4 findings
HIGH New obfuscated file: dist/components/dev-console/console-trigger.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/dev-console/developer-console-modal.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/components/dev-console/icons.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.