← Home

@copilotkit/runtime

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

copilotkit

Keywords

aiassistantautomationcopilotcopilotkitjavascriptnextjsnodejsreacttanstack-intenttextarea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@copilotkit/channels-intelligence AI (dependencies): Same-org first-party sibling package, not a third-party unvetted dep. ai
phantom-deps phantom-dep:@copilotkit/channels-intelligence AI (phantom-deps): Same org scope, used indirectly; benign. ai
dependencies unvetted-dep:@copilotkit/channels-core AI (dependencies): First-party CopilotKit sibling package, not an unrelated third-party dep. ai
phantom-deps phantom-dep:@langchain/openai AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:tiktoken AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
dependencies unvetted-dep:@agentwire/proto AI (dependencies): Legit sibling protocol lib, no malicious behavior evidenced. ai
dependencies unvetted-dep:@agentwire/core AI (dependencies): Legit sibling protocol lib, no malicious behavior evidenced. ai
dependencies unvetted-dep:@agentwire/encoder AI (dependencies): Legit sibling protocol lib, no malicious behavior evidenced. ai
phantom-deps phantom-dep:@agentwire/encoder AI (phantom-deps): Used via config/build, not a direct import concern. ai
phantom-deps phantom-dep:@agentwire/proto AI (phantom-deps): Used via config/build, not a direct import concern. ai
phantom-deps phantom-dep:@agentwire/core AI (phantom-deps): Used via config/build, not a direct import concern. ai
dependencies unvetted-dep:@agentwire/client AI (dependencies): Legit sibling protocol lib, no malicious behavior evidenced. ai
provenance regressed-provenance AI (provenance): Manual publish by known maintainer copilotkit; no material diff, benign for this package. ai
dependencies unvetted-dep:type-graphql AI (dependencies): type-graphql 2.0.0-rc.1 is intentionally pinned by this package; stable pre-release dependency, not a supply-chain risk. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is from the same @ag-ui/* namespace already used by this package; consistent with incremental MCP middleware additions. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Declared dep used transitively/conditionally; stable for this package. ai
semgrep semgrep:env-spread AI (semgrep): Fires in test file only; saving/restoring process.env for test isolation. ai
phantom-deps phantom-dep:@segment/analytics-node AI (phantom-deps): Analytics dep conditionally loaded; stable for this package. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance; stable for this package. ai
phantom-deps phantom-dep:@types/ip AI (phantom-deps): Type-only package, framework-scoped; stable FP for this package. ai
phantom-deps phantom-dep:ip AI (phantom-deps): ip is a declared runtime dep used indirectly via framework conventions; stable FP for this package. ai
phantom-deps phantom-dep:express AI (phantom-deps): express is a declared runtime dep used as a peer/optional integration; phantom-dep heuristic fires on config-only references. ai
phantom-deps phantom-dep:@ag-ui/encoder AI (phantom-deps): Declared in both dependencies and peerDependencies; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:@ag-ui/proto AI (phantom-deps): Declared in both dependencies and peerDependencies; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:@ag-ui/core AI (phantom-deps): Declared in both dependencies and peerDependencies; phantom-dep heuristic is a false positive here. ai
phantom-deps phantom-dep:partial-json AI (phantom-deps): Declared dep in a bundled runtime; heuristic false positive for this package. ai
phantom-deps phantom-dep:@graphql-yoga/plugin-defer-stream AI (phantom-deps): Used in GraphQL yoga integration; heuristic false positive for this package. ai
phantom-deps phantom-dep:@hono/node-server AI (phantom-deps): Used in optional v2/hono export path; heuristic false positive for this package. ai
phantom-deps phantom-dep:@scarf/scarf AI (phantom-deps): Scarf analytics loaded via config/postinstall hooks, not direct import; stable false positive. ai
phantom-deps phantom-dep:class-validator AI (phantom-deps): Used with type-graphql/class-transformer ecosystem; heuristic false positive. ai
phantom-deps phantom-dep:ws AI (phantom-deps): Large runtime package; ws is a transitive/peer dep used indirectly — stable false positive. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get used for typed dynamic property access in agent config iteration; standard TypeScript pattern, not obfuscation. ai
semgrep semgrep:etc-passwd-access AI (semgrep): Fires on a test file string literal simulating an error message, not actual /etc/passwd access. ai

Versions (showing 100 of 137)

Version Deps Published
1.63.2 43 / 22
1.63.1 43 / 22
1.63.0 42 / 22
1.62.3 41 / 21
1.62.2 41 / 21
1.62.1 41 / 21
1.62.0 41 / 21
1.61.2 41 / 21
1.61.1 41 / 21
1.61.0 41 / 21
1.60.2 41 / 21
1.60.1 41 / 21
1.60.0 41 / 21
1.59.5 41 / 21
1.59.4 41 / 21
1.59.3 40 / 21
1.59.2 40 / 21
1.59.1 40 / 21
1.59.0 40 / 21
1.58.0 40 / 21
1.57.4 40 / 21
1.57.3 40 / 20
1.57.2 40 / 20
1.57.1 40 / 20
1.57.0 40 / 20
1.56.5 40 / 20
1.56.4 40 / 20
1.56.3 40 / 20
1.56.2 40 / 20
1.56.1 40 / 20
1.56.0 40 / 20
1.55.3 40 / 20
1.55.2 40 / 20
1.55.1 40 / 19
1.55.0 40 / 19
1.54.1 26 / 11
1.54.0 26 / 11
1.53.0 26 / 11
1.52.1 26 / 11
1.52.0 23 / 11
1.51.4 23 / 15
1.51.3 23 / 15
1.51.2 23 / 15
1.51.1 17 / 18
1.51.0 17 / 18
1.50.1 23 / 15
1.50.0 23 / 15
1.10.6 26 / 16
1.10.5 31 / 16
1.10.4 31 / 16
1.10.3 31 / 16
1.10.2 31 / 16
1.10.1 31 / 16
1.10.0 31 / 16
1.9.3 33 / 16
1.9.2 30 / 16
1.9.1 30 / 16
1.9.0 30 / 16
1.8.14 28 / 16
1.8.13 28 / 16
1.8.12 28 / 16
1.8.11 28 / 15
1.8.10 28 / 15
1.8.9 28 / 15
1.8.8 28 / 15
1.8.7 28 / 15
1.8.6 28 / 15
1.8.5 28 / 15
1.8.4 24 / 15
1.8.3 24 / 15
1.8.2 24 / 15
1.8.1 24 / 15
1.8.0 24 / 15
1.7.1 24 / 15
1.7.0 24 / 15
1.6.0 24 / 15
1.5.20 23 / 15
1.5.19 23 / 15
1.5.18 23 / 15
1.5.17 23 / 15
1.5.16 23 / 15
1.5.15 23 / 15
1.5.14 23 / 15
1.5.13 23 / 15
1.5.12 23 / 15
1.5.11 23 / 15
1.5.10 23 / 15
1.5.9 23 / 15
1.5.8 23 / 15
1.5.7 23 / 15
1.5.6 23 / 15
1.5.5 23 / 15
1.5.4 23 / 15
1.5.3 23 / 15
1.5.2 23 / 15
1.5.1 23 / 15
1.5.0 23 / 15
1.4.8 23 / 15
1.4.7 23 / 15
1.4.6 23 / 15
Showing 100 of 137 Next page →

v1.63.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.63.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.63.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.61.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.61.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.61.0

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: GitHub Actions → copilotkit (on 2026-06-18, known maintainer) provenance

This version was published by a different npm account (copilotkit) than the most recent previously approved version (GitHub Actions) on 2026-06-18, but copilotkit is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.60.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.60.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.59.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.59.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.59.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.59.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.57.4

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: copilotkit → GitHub Actions (on 2026-05-21) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-05-21. This could indicate a legitimate maintainer transition or an account compromise.

v1.57.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.57.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.56.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.56.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.56.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.55.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.54.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.51.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.51.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.51.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.51.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.50.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.10.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.