@dxos/app-graph
Constructs knowledge graphs for the purpose of building applications on top of
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): DXOS monorepo migrated CI publisher from dxos-bot to GitHub Actions; SLSA attestation confirms legitimate CI pipeline. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Part of DXOS org CI migration; consistent with publisher change to GitHub Actions across the monorepo. | ai | |
| phantom-deps | phantom-dep:@dxos/keys | AI (phantom-deps): Same-org dep newly added to package.json; phantom-dep heuristic likely misses indirect usage in bundled output. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal DXOS monorepo package; sparse README is expected for org-internal libs, not a spam indicator. | ai | |
| phantom-deps | phantom-dep:@dxos/live-object | AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo transitive re-exports. | ai | |
| phantom-deps | phantom-dep:@dxos/echo-signals | AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo transitive re-exports. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 0.9.0 | 8 / 15 | |
| 0.8.3 | 11 / 17 | |
| 0.8.2 | 10 / 15 | |
| 0.8.1 | 10 / 11 | |
| 0.8.0 | 10 / 11 | |
| 0.7.4 | 10 / 11 | |
| 0.7.3 | 10 / 11 | |
| 0.7.2 | 9 / 11 | |
| 0.7.1 | 9 / 11 | |
| 0.7.0 | 9 / 11 | |
| 0.6.13 | 9 / 11 | |
| 0.6.12 | 9 / 11 | |
| 0.6.11 | 9 / 11 | |
| 0.6.10 | 9 / 11 | |
| 0.6.9 | 9 / 11 | |
| 0.6.8 | 9 / 11 | |
| 0.6.7 | 9 / 11 | |
| 0.6.6 | 9 / 11 | |
| 0.6.5 | 9 / 11 | |
| 0.6.4 | 9 / 11 | |
| 0.6.3 | 9 / 11 | |
| 0.6.2 | 7 / 11 | |
| 0.6.1 | 7 / 11 | |
| 0.6.0 | 7 / 11 | |
| 0.5.8 | 7 / 11 | |
| 0.5.7 | 7 / 11 | |
| 0.5.6 | 7 / 11 | |
| 0.5.5 | 7 / 11 | |
| 0.5.4 | 7 / 11 | |
| 0.5.3 | 7 / 11 | |
| 0.5.2 | 7 / 11 |
v0.8.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.