← Home

@doist/todoist-mcp

23
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ricardoisthenningmujvalenteantondoistjefcurtisdmgaweldoistbotfbidugoncalossilvaomar.doist.comscottatdoisternestodoist

Keywords

todoistmcpaitools

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publisher with SLSA provenance; consistent with Doist org's documented CI/CD pipeline. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): dompurify is a legitimate sanitization dep; phantom-dep heuristic fires because it's used indirectly via bundled app code. ai

Versions (showing 23 of 23)

Version Deps Published
12.1.1 7 / 31
12.1.0 7 / 31
12.0.0 7 / 31
11.0.0 7 / 31
10.5.0 7 / 31
10.4.2 7 / 31
10.4.1 7 / 31
10.4.0 7 / 31
10.3.3 7 / 31
10.3.2 7 / 31
10.3.1 7 / 31
10.3.0 7 / 31
10.2.0 7 / 31
10.1.6 7 / 31
10.1.5 7 / 31
10.1.4 7 / 31
10.1.3 7 / 31
10.1.2 7 / 31
10.1.1 7 / 31
10.1.0 7 / 30
10.0.0 7 / 30
9.0.0 7 / 30
0.0.1 0 / 0

v12.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v10.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v10.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v10.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.