@deepagents/text2sql
AI-powered natural language to SQL. Ask questions in plain English, get executable queries.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Unchanged from prior approved version; not a regression. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/react | AI (phantom-deps): Config-referenced dependency; consistent with package's adapter/plugin pattern. | ai | |
| dependencies | unvetted-dep:evalite | AI (dependencies): evalite is an evaluation framework; appropriate for a text2sql package with LLM evaluation features. | ai | |
| dependencies | unvetted-dep:xlsx | AI (dependencies): xlsx is a well-known spreadsheet library; its use is expected given the package exports a /spreadsheet adapter. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): proper-lockfile is a well-known, stable utility; addition is contextually appropriate for this package. | ai | |
| phantom-deps | phantom-dep:@deepagents/evals | AI (phantom-deps): Same-org package used for evals; likely loaded by convention rather than direct import. | ai | |
| phantom-deps | phantom-dep:@google-cloud/bigquery | AI (phantom-deps): Framework-scoped BigQuery adapter; loaded by convention as noted by analyzer. | ai | |
| phantom-deps | phantom-dep:pg | AI (phantom-deps): pg is a declared runtime dep for the postgres adapter; phantom-dep heuristic fires on adapter-pattern packages. | ai | |
| phantom-deps | phantom-dep:nano-spawn | AI (phantom-deps): Utility dep; referenced in config not direct import. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): CLI utility dep; likely used in build/config context, not direct import. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/openai | AI (phantom-deps): AI SDK adapter dep; referenced in config not direct import. | ai | |
| phantom-deps | phantom-dep:autoevals | AI (phantom-deps): autoevals is a declared dep used in config/eval files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:evalite | AI (phantom-deps): evalite is a declared dep used in config/eval files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:openai | AI (phantom-deps): openai is a declared runtime dep; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 5.0.0 | 17 / 7 | |
| 4.3.0 | 18 / 7 | |
| 4.1.0 | 23 / 4 | |
| 4.0.0 | 23 / 4 | |
| 2.2.0 | 22 / 3 | |
| 2.1.0 | 22 / 3 | |
| 1.0.0 | 22 / 3 | |
| 0.32.0 | 21 / 2 | |
| 0.20.0 | 19 / 1 | |
| 0.18.0 | 19 / 1 | |
| 0.17.1 | 19 / 1 | |
| 0.17.0 | 19 / 1 | |
| 0.16.0 | 21 / 1 | |
| 0.15.1 | 20 / 1 | |
| 0.13.0 | 19 / 0 | |
| 0.12.1 | 19 / 0 | |
| 0.12.0 | 19 / 0 | |
| 0.11.0 | 19 / 0 | |
| 0.10.2 | 18 / 0 | |
| 0.10.1 | 18 / 0 | |
| 0.10.0 | 18 / 0 | |
| 0.9.0 | 17 / 0 | |
| 0.8.1 | 16 / 0 | |
| 0.8.0 | 16 / 0 | |
| 0.7.0 | 16 / 0 | |
| 0.6.0 | 16 / 0 | |
| 0.3.1 | 11 / 0 | |
| 0.3.0 | 11 / 0 | |
| 0.2.3 | 11 / 0 | |
| 0.2.2 | 11 / 0 | |
| 0.2.1 | 11 / 0 | |
| 0.2.0 | 11 / 0 |
v5.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.