@copilotkit/runtime-client-gql
<img src="https://github.com/user-attachments/assets/0a6b64d9-e193-4940-a3f6-60334ac34084" alt="banner" style="border-radius: 12px; border: 2px solid #d6d4fa;" />
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/chunk-SVJN2STA.mjs | AI (source-diff): esbuild chunk with js-tokens bundle; build artifact. | ai | |
| source-diff | net-exec-file:dist/chunk-A4INSSNE.mjs | AI (source-diff): esbuild-bundled tokenizer/test output, no hostile destination; stable for this package. | ai | |
| source-diff | net-exec-file:dist/chunk-L6PM6AT3.mjs | AI (source-diff): tsup-generated chunk with js-tokens tokenizer; build artifact. | ai | |
| source-diff | net-exec-file:dist/message-conversion/roundtrip-conversion.test.js | AI (source-diff): Bundled esbuild test output; false positive. | ai | |
| source-diff | net-exec-file:dist/message-conversion/gql-to-agui.test.js | AI (source-diff): Bundled esbuild test output; false positive. | ai | |
| source-diff | net-exec-file:dist/message-conversion/agui-to-gql.test.js | AI (source-diff): Bundled esbuild test output (js-tokens); no real net+exec payload. | ai | |
| source-diff | obfuscated-file:dist/graphql/@generated/index.js | AI (source-diff): GraphQL codegen artifact. | ai | |
| source-diff | obfuscated-file:dist/graphql/@generated/gql.js | AI (source-diff): GraphQL codegen artifact. | ai | |
| source-diff | obfuscated-file:dist/graphql/@generated/graphql.js | AI (source-diff): GraphQL codegen artifact. | ai | |
| source-diff | obfuscated-file:dist/graphql/@generated/gql.d.ts | AI (source-diff): codegen type decl with long lines. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Growth is bundled/codegen dist, not injected payload. | ai | |
| source-diff | large-new-source-files | AI (source-diff): GraphQL codegen + bundle emits many dist files; benign for this package. | ai | |
| source-diff | obfuscated-file:dist/graphql/definitions/queries.js | AI (source-diff): GraphQL codegen + bundle output. | ai | |
| source-diff | obfuscated-file:src/graphql/@generated/gql.ts | AI (source-diff): GraphQL codegen generated file, long query strings. | ai | |
| phantom-deps | phantom-dep:class-validator | AI (phantom-deps): Declared in dependencies; used for runtime validation. Stable false positive. | ai | |
| phantom-deps | phantom-dep:class-transformer | AI (phantom-deps): Declared in dependencies; used for data transformation. Stable false positive. | ai | |
| phantom-deps | phantom-dep:@copilotkit/runtime | AI (phantom-deps): Same-org sibling dependency; used by this package. Stable false positive. | ai | |
| phantom-deps | phantom-dep:wonka | AI (phantom-deps): Declared in dependencies; used by urql/graphql stack. Stable false positive. | ai | |
| source-diff | obfuscated-file:src/graphql/@generated/graphql.ts | AI (source-diff): generated GraphQL types, long lines from schema | ai | |
| source-diff | obfuscated-file:dist/index.js | AI (source-diff): esbuild bundle output, not obfuscation | ai | |
| source-diff | obfuscated-file:dist/client/index.js | AI (source-diff): esbuild bundle output, not obfuscation | ai | |
| source-diff | obfuscated-file:dist/client/CopilotRuntimeClient.js | AI (source-diff): esbuild bundle output, not obfuscation | ai | |
| source-diff | obfuscated-file:dist/graphql/definitions/mutations.js | AI (source-diff): esbuild bundle output, not obfuscation | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA provenance; legitimate for this org. | ai | |
| provenance | no-provenance | AI (provenance): CopilotKit monorepo consistently publishes without Sigstore provenance; stable false positive for this package. | ai |
Versions (showing 30 of 130)
| Version | Deps | Published |
|---|---|---|
| 1.3.14 | 9 / 16 | |
| 1.3.13 | 9 / 16 | |
| 1.3.12 | 9 / 16 | |
| 1.3.11 | 9 / 16 | |
| 1.3.10 | 9 / 16 | |
| 1.3.9 | 9 / 16 | |
| 1.3.8 | 9 / 16 | |
| 1.3.7 | 9 / 16 | |
| 1.3.6 | 9 / 16 | |
| 1.3.5 | 9 / 16 | |
| 1.3.4 | 9 / 16 | |
| 1.3.3 | 9 / 16 | |
| 1.3.2 | 9 / 16 | |
| 1.3.1 | 9 / 16 | |
| 1.3.0 | 9 / 16 | |
| 1.2.1 | 9 / 16 | |
| 1.2.0 | 9 / 16 | |
| 1.1.2 | 9 / 16 | |
| 1.1.1 | 9 / 16 | |
| 1.1.0 | 9 / 16 | |
| 1.0.9 | 9 / 16 | |
| 1.0.8 | 9 / 16 | |
| 1.0.7 | 9 / 15 | |
| 1.0.6 | 9 / 15 | |
| 1.0.5 | 9 / 15 | |
| 1.0.4 | 9 / 15 | |
| 1.0.3 | 10 / 15 | |
| 1.0.2 | 10 / 15 | |
| 1.0.1 | 10 / 15 | |
| 1.0.0 | 10 / 15 |
v1.3.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.