@desplega.ai/agent-swarm
Multi-agent orchestration for Claude Code, Codex, Gemini CLI, and other AI coding assistants
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@earendil-works/pi-agent-core | AI (phantom-deps): Referenced in config/re-exported; common for plugin-style deps. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Used in secret-scrubber utility that filters keys by sensitivity — expected pattern. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): AES key parsing from hex/base64 input in crypto bootstrap — legitimate cryptographic use. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): AES key parsing from base64 input in crypto bootstrap — legitimate cryptographic use. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP is 127.0.0.1 localhost loopback for OAuth callback binding — not exfiltration. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreads process.env only to add a single override key for a subprocess; not exfiltration. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Type-only package; framework-scoped, not directly imported at runtime. | ai | |
| phantom-deps | phantom-dep:zod-to-json-schema | AI (phantom-deps): Referenced in config/build files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-devtools-core | AI (phantom-deps): Dev tooling dependency; loaded by convention not direct import. | ai | |
| phantom-deps | phantom-dep:@mariozechner/pi-agent-core | AI (phantom-deps): Plugin/config reference; stable false positive for this package. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Used in sandboxed code-match executor with explicit SANDBOX_KEYS scoping — documented pattern. | ai |
Versions (showing 51 of 99)
| Version | Deps | Published |
|---|---|---|
| 1.92.0 | 39 / 4 | |
| 1.91.0 | 39 / 4 | |
| 1.90.0 | 39 / 4 | |
| 1.89.0 | 39 / 4 | |
| 1.88.0 | 39 / 4 | |
| 1.87.0 | 39 / 4 | |
| 1.86.0 | 38 / 4 | |
| 1.85.0 | 38 / 4 | |
| 1.84.1 | 38 / 4 | |
| 1.84.0 | 38 / 4 | |
| 1.83.2 | 38 / 4 | |
| 1.83.1 | 38 / 4 | |
| 1.83.0 | 38 / 4 | |
| 1.82.0 | 38 / 4 | |
| 1.81.1 | 38 / 4 | |
| 1.81.0 | 38 / 4 | |
| 1.80.3 | 38 / 4 | |
| 1.80.2 | 38 / 4 | |
| 1.80.1 | 38 / 4 | |
| 1.80.0 | 38 / 4 | |
| 1.79.4 | 33 / 4 | |
| 1.79.3 | 33 / 4 | |
| 1.79.2 | 33 / 4 | |
| 1.79.1 | 33 / 4 | |
| 1.79.0 | 33 / 4 | |
| 1.78.1 | 33 / 4 | |
| 1.78.0 | 33 / 4 | |
| 1.77.3 | 33 / 4 | |
| 1.77.2 | 33 / 4 | |
| 1.77.1 | 33 / 4 | |
| 1.77.0 | 33 / 4 | |
| 1.76.3 | 33 / 4 | |
| 1.76.2 | 33 / 4 | |
| 1.76.1 | 33 / 4 | |
| 1.76.0 | 33 / 4 | |
| 1.75.0 | 33 / 4 | |
| 1.74.4 | 33 / 4 | |
| 1.74.3 | 33 / 4 | |
| 1.74.2 | 33 / 4 | |
| 1.74.1 | 33 / 4 | |
| 1.74.0 | 33 / 4 | |
| 1.73.5 | 33 / 4 | |
| 1.73.4 | 32 / 3 | |
| 1.73.3 | 32 / 3 | |
| 1.73.2 | 32 / 3 | |
| 1.73.1 | 32 / 3 | |
| 1.73.0 | 32 / 3 | |
| 1.72.1 | 32 / 3 | |
| 1.72.0 | 32 / 3 | |
| 1.71.2 | 31 / 3 | |
| 1.71.1 | 31 / 3 |
v1.92.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.91.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.90.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.89.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.88.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.87.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.86.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.85.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.84.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.84.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.83.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.83.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.83.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.82.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.81.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.81.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.80.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.80.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.80.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.80.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.79.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.79.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.79.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.79.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.79.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.78.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.78.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.77.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.77.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.77.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.77.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.76.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.76.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.76.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.76.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.75.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.74.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.74.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.74.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.74.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.74.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.73.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.73.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.73.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.73.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.73.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.73.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.72.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.71.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.71.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.