@dxos/devtools
Standalone devtool app used to inspect DXOS client state
3
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
richburdonmarik_dwittjosiahdxos-botmykola-vrmchk
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher change from dxos-bot to GitHub Actions reflects CI pipeline migration; SLSA attestation confirms integrity. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of yarolegovich consistent with org-level CI publishing transition; SLSA provenance corroborates legitimate publish. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are all @dxos/* monorepo packages or known ecosystem libs; consistent with feature expansion, not supply chain attack. | ai | |
| phantom-deps | phantom-dep:@types/bytes | AI (phantom-deps): Type-only package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-json-tree | AI (phantom-deps): Config-referenced dep in monorepo build; stable false positive. | ai | |
| phantom-deps | phantom-dep:@effect/platform | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is a transitive/config-referenced dep in a monorepo build; not a real phantom risk. | ai | |
| phantom-deps | phantom-dep:@dxos/react-edge-client | AI (phantom-deps): Same-org sibling dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-syntax-highlighter | AI (phantom-deps): Config-referenced dep; stable false positive. | ai | |
| provenance | no-provenance | AI (provenance): DXOS monorepo bot publishing; no provenance is consistent across all versions. | ai | |
| phantom-deps | phantom-dep:use-resize-observer | AI (phantom-deps): Config-referenced dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:luxon | AI (phantom-deps): luxon used via chartjs-adapter-luxon; config-referenced, not a real phantom risk. | ai | |
| phantom-deps | phantom-dep:react-is | AI (phantom-deps): react-is is a framework-scoped dep referenced in config; stable false positive. | ai |