← Home

@dxos/plugin-graph

DXOS Surface plugin for constructing knowledge graphs

16
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

richburdonmarik_dwittjosiahdxos-botmykola-vrmchk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): dxos-bot → GitHub Actions is an org-internal CI migration; SLSA attestation confirms provenance. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer removal aligns with org-level CI automation takeover; consistent with DXOS publishing pattern. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps are @dxos-scoped packages at matching 0.9.0 version; consistent with monorepo refactor. ai
bogus-package bogus-package AI (bogus-package): DXOS monorepo packages consistently have minimal READMEs; not a spam/phishing indicator for this org. ai
phantom-deps phantom-dep:@preact-signals/safe-react AI (phantom-deps): Referenced in config files per finding; not a real phantom dep for this package. ai
phantom-deps phantom-dep:@dxos/async AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic unreliable for bundled packages. ai
phantom-deps phantom-dep:@dxos/debug AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic unreliable for bundled packages. ai

Versions (showing 16 of 16)

Version Deps Published
0.9.0 8 / 10
0.8.3 5 / 10
0.8.2 5 / 10
0.8.1 5 / 7
0.8.0 5 / 7
0.7.4 5 / 7
0.7.3 5 / 7
0.7.2 5 / 7
0.7.1 5 / 7
0.7.0 5 / 7
0.6.13 3 / 7
0.6.12 3 / 7
0.6.11 3 / 7
0.6.10 3 / 7
0.6.9 3 / 7
0.6.8 3 / 7

v0.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.