@daytona/opencode
OpenCode plugin that automatically runs all sessions in Daytona sandboxes for isolated, reproducible development environments
15
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
mivandamdzajagdraganic
Keywords
daytonaopencodeplugin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-spread | AI (semgrep): Git manager intentionally spreads process.env to pass git credentials; standard pattern for git subprocess invocation. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Git manager plugin legitimately shells out to git; child_process use is expected and scoped to git operations. | ai | |
| phantom-deps | phantom-dep:tar | AI (phantom-deps): Plugin framework loads deps by convention; phantom-dep is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:pathe | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:busboy | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:fast-glob | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:form-data | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@iarna/toml | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:shell-quote | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:expand-tilde | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:isomorphic-ws | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-s3 | AI (phantom-deps): Framework-scoped; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@daytona/api-client | AI (phantom-deps): Same org scope; loaded by plugin framework convention. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/lib-storage | AI (phantom-deps): Framework-scoped; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-node | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/resources | AI (phantom-deps): Plugin framework loads deps by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@daytona/toolbox-api-client | AI (phantom-deps): Same org scope; loaded by plugin framework convention. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 0.190.1 | 27 / 0 | |
| 0.190.0 | 27 / 0 | |
| 0.189.0 | 27 / 0 | |
| 0.187.0 | 27 / 0 | |
| 0.186.0 | 27 / 0 | |
| 0.185.0 | 27 / 0 | |
| 0.184.0 | 27 / 0 | |
| 0.183.0 | 27 / 0 | |
| 0.182.0 | 27 / 0 | |
| 0.179.0 | 27 / 0 | |
| 0.173.0 | 27 / 0 | |
| 0.171.0 | 27 / 0 | |
| 0.169.0 | 27 / 0 | |
| 0.167.0 | 27 / 0 | |
| 0.166.0 | 27 / 0 |
v0.190.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.