← Home

@dxos/plugin-assistant

Assistant plugin

4
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

richburdonmarik_dwittjosiahdxos-botmykola-vrmchk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@effect/experimental AI (phantom-deps): Referenced in config; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@dxos/react-ui-graph AI (phantom-deps): Same-org dep declared for transitive/optional use; stable false positive for this monorepo package. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer removal consistent with org-level CI/CD transition; SLSA attestation confirms legitimate publish pipeline. ai
source-diff large-new-source-files AI (source-diff): Large file count reflects major version refactor of a complex plugin; no obfuscation or malicious content indicated. ai
license uncommon-license:FSL-1.1-Apache-2.0 AI (license): FSL-1.1-Apache-2.0 is the consistent license used across all DXOS packages. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps are @dxos/* org packages or established ecosystem libs (effect, @effect/*, @radix-ui/*); consistent with major refactor. ai
provenance publisher-changed AI (provenance): dxos-bot → GitHub Actions is an org-internal CI publisher transition, consistent with SLSA provenance attestation. ai
bogus-package bogus-package AI (bogus-package): DXOS monorepo plugin; sparse README is typical for internal ecosystem packages, not spam. ai
provenance no-provenance AI (provenance): DXOS packages consistently lack provenance attestation; stable false positive for this org. ai

Versions (showing 4 of 4)

Version Deps Published
0.10.0 68 / 24
0.9.0 65 / 24
0.8.3 69 / 22
0.8.2 66 / 22

v0.10.0

2 findings
HIGH Publisher changed: dxos-bot → GitHub Actions (on 2026-07-02) provenance

This version was published by a different npm account than previous versions on 2026-07-02. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.