@cursor/sdk-linux-x64
Ripgrep binary for linux-x64, bundled for @cursor/sdk.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): Platform binary package ships prebuilt binaries (rg, cursorsandbox) by design. | ai | |
| bogus-package | bogus-package | AI (bogus-package): No deps, minimal README expected for a platform-specific binary distribution package. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 1.0.23 | 0 / 0 | |
| 1.0.22 | 0 / 0 | |
| 1.0.19 | 0 / 0 | |
| 1.0.18 | 0 / 0 | |
| 1.0.17 | 0 / 0 | |
| 1.0.16 | 0 / 0 | |
| 1.0.15 | 0 / 0 | |
| 1.0.14 | 0 / 0 | |
| 1.0.13 | 0 / 0 | |
| 1.0.12 | 0 / 0 | |
| 1.0.11 | 0 / 0 | |
| 1.0.10 | 0 / 0 | |
| 1.0.9 | 0 / 0 | |
| 1.0.8 | 0 / 0 | |
| 1.0.7 | 0 / 0 |
v1.0.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.22
2 findingsThis version was published by a different npm account than previous versions on 2026-06-25. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.