← Home

@decocms/runtime

A TypeScript framework for building MCP (Model Context Protocol) servers with first-class support for tools, prompts, resources, OAuth authentication, and event-driven architectures.

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

camudonicacioliveiragimenes-decocxcrazydeviljonasjesusfirstdoitvinventura

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Internal monorepo package under @decocms org; missing metadata is expected, not a spam/malware indicator. ai
semgrep semgrep:etc-passwd-access AI (semgrep): All 18 hits are in test files asserting path traversal is blocked — not credential access. ai
semgrep semgrep:env-spread AI (semgrep): Spreading process.env into request bindings is standard edge-runtime pattern for this package. ai
phantom-deps phantom-dep:@cloudflare/workers-types AI (phantom-deps): Type-only package used by convention in Cloudflare Workers projects; not directly imported. ai

Versions (showing 51 of 53)

View all versions
Version Deps Published
2.3.6 6 / 4
2.3.5 6 / 4
2.3.4 6 / 4
2.3.3 6 / 4
2.3.2 6 / 4
2.3.1 6 / 4
2.3.0 6 / 4
2.2.0 6 / 4
2.1.4 6 / 4
2.1.3 6 / 4
2.1.2 6 / 4
2.1.1 6 / 4
2.1.0 7 / 4
2.0.2 7 / 4
2.0.1 6 / 4
2.0.0 6 / 4
1.6.5 6 / 4
1.6.4 7 / 4
1.6.3 7 / 4
1.6.2 7 / 4
1.6.1 7 / 4
1.6.0 7 / 4
1.5.0 7 / 4
1.4.0 7 / 4
1.3.1 7 / 4
1.3.0 7 / 4
1.2.15 7 / 4
1.2.14 7 / 4
1.2.13 7 / 4
1.2.12 7 / 3
1.2.11 7 / 3
1.2.10 7 / 3
1.2.9 7 / 3
1.2.8 7 / 3
1.2.7 7 / 3
1.2.6 7 / 3
1.2.5 7 / 3
1.2.4 7 / 3
1.2.3 7 / 3
1.2.2 7 / 3
1.2.1 7 / 3
1.2.0 7 / 3
1.1.3 7 / 3
1.1.2 7 / 3
1.1.1 7 / 3
1.1.0 7 / 3
1.0.3 8 / 3
1.0.2 8 / 3
0.28.0 14 / 4
0.26.0 14 / 4
0.25.1 12 / 4

v2.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.