← Home

@deepagents/text2sql

AI-powered natural language to SQL. Ask questions in plain English, get executable queries.

32
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ezzabuzaid

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): Unchanged from prior approved version; not a regression. ai
phantom-deps phantom-dep:@ai-sdk/react AI (phantom-deps): Config-referenced dependency; consistent with package's adapter/plugin pattern. ai
dependencies unvetted-dep:evalite AI (dependencies): evalite is an evaluation framework; appropriate for a text2sql package with LLM evaluation features. ai
dependencies unvetted-dep:xlsx AI (dependencies): xlsx is a well-known spreadsheet library; its use is expected given the package exports a /spreadsheet adapter. ai
publish-pattern new-deps-added AI (publish-pattern): proper-lockfile is a well-known, stable utility; addition is contextually appropriate for this package. ai
phantom-deps phantom-dep:@deepagents/evals AI (phantom-deps): Same-org package used for evals; likely loaded by convention rather than direct import. ai
phantom-deps phantom-dep:@google-cloud/bigquery AI (phantom-deps): Framework-scoped BigQuery adapter; loaded by convention as noted by analyzer. ai
phantom-deps phantom-dep:pg AI (phantom-deps): pg is a declared runtime dep for the postgres adapter; phantom-dep heuristic fires on adapter-pattern packages. ai
phantom-deps phantom-dep:nano-spawn AI (phantom-deps): Utility dep; referenced in config not direct import. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): CLI utility dep; likely used in build/config context, not direct import. ai
phantom-deps phantom-dep:@ai-sdk/openai AI (phantom-deps): AI SDK adapter dep; referenced in config not direct import. ai
phantom-deps phantom-dep:autoevals AI (phantom-deps): autoevals is a declared dep used in config/eval files; stable false positive for this package. ai
phantom-deps phantom-dep:evalite AI (phantom-deps): evalite is a declared dep used in config/eval files; stable false positive for this package. ai
phantom-deps phantom-dep:openai AI (phantom-deps): openai is a declared runtime dep; phantom-dep heuristic false positive for this package. ai

Versions (showing 32 of 32)

Version Deps Published
5.0.0 17 / 7
4.3.0 18 / 7
4.1.0 23 / 4
4.0.0 23 / 4
2.2.0 22 / 3
2.1.0 22 / 3
1.0.0 22 / 3
0.32.0 21 / 2
0.20.0 19 / 1
0.18.0 19 / 1
0.17.1 19 / 1
0.17.0 19 / 1
0.16.0 21 / 1
0.15.1 20 / 1
0.13.0 19 / 0
0.12.1 19 / 0
0.12.0 19 / 0
0.11.0 19 / 0
0.10.2 18 / 0
0.10.1 18 / 0
0.10.0 18 / 0
0.9.0 17 / 0
0.8.1 16 / 0
0.8.0 16 / 0
0.7.0 16 / 0
0.6.0 16 / 0
0.3.1 11 / 0
0.3.0 11 / 0
0.2.3 11 / 0
0.2.2 11 / 0
0.2.1 11 / 0
0.2.0 11 / 0

v5.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.