← Home

@dxos/plugin-attention

Plugin for attention

16
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

richburdonmarik_dwittjosiahdxos-botmykola-vrmchk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): dxos-bot → GitHub Actions is an org-internal CI migration; SLSA attestation confirms build integrity. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with org-level CI migration; same GitHub org (dxos/dxos) maintains the package. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps are @dxos/* at matching 0.9.0 version — coordinated monorepo release pattern. ai
phantom-deps phantom-dep:@dxos/echo-signals AI (phantom-deps): Same-org dep; monorepo build pattern. ai
bogus-package bogus-package AI (bogus-package): DXOS monorepo sub-package; sparse README and no keywords are normal for internal plugin packages. ai
phantom-deps phantom-dep:@preact-signals/safe-react AI (phantom-deps): Referenced in config files per finding; not a phantom in practice. ai
phantom-deps phantom-dep:@dxos/echo AI (phantom-deps): Same-org dep; may be used transitively or via re-exports in monorepo build. ai
phantom-deps phantom-dep:@dxos/echo-schema AI (phantom-deps): Same-org dep; monorepo build pattern. ai

Versions (showing 16 of 16)

Version Deps Published
0.9.0 9 / 3
0.8.3 9 / 3
0.8.2 9 / 3
0.8.1 6 / 3
0.8.0 6 / 3
0.7.4 6 / 3
0.7.3 6 / 3
0.7.2 6 / 3
0.7.1 6 / 3
0.7.0 6 / 3
0.6.13 6 / 3
0.6.12 6 / 3
0.6.11 6 / 3
0.6.10 6 / 3
0.6.9 6 / 3
0.6.8 6 / 3

v0.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.