@dxos/protocols
Protobuf definitions for DXOS protocols.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/edge/messenger_pb.ts | AI (source-diff): Base64 protobuf descriptor from protoc-gen-es codegen, not a payload. | ai | |
| source-diff | encoded-string-file:dist/src/buf/proto/gen/dxos/config_pb.js | AI (source-diff): Base64 protobuf descriptor from protoc-gen-es codegen, not a payload. | ai | |
| source-diff | encoded-string-file:dist/src/buf/proto/gen/dxos/edge/messenger_pb.js | AI (source-diff): Base64 protobuf descriptor from protoc-gen-es codegen, not a payload. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/buf/proto/gen/dxos/config_pb.js | AI (source-diff): Base64 protobuf descriptor in generated buf codegen, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/esm/src/buf/proto/gen/dxos/config_pb.js | AI (source-diff): Base64 protobuf descriptor in generated buf codegen, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/buf/proto/gen/dxos/halo/credentials_pb.js | AI (source-diff): Base64 protobuf descriptor in generated buf codegen, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/esm/src/buf/proto/gen/dxos/halo/credentials_pb.js | AI (source-diff): Base64 protobuf descriptor in generated buf codegen, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Migration to buf codegen adds many generated files; not injected code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @bufbuild/protobuf is the official runtime for the new codegen, expected addition. | ai | |
| source-diff | obfuscated-file:dist/cjs/src/buf/proto/gen/dxos/bot_pb.js | AI (source-diff): Base64 protobuf descriptor in generated buf codegen, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/esm/src/buf/proto/gen/dxos/bot_pb.js | AI (source-diff): Base64 protobuf descriptor in generated buf codegen, not obfuscation. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/bot_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/mesh/bridge_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/edge/calls_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/config_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/halo/credentials_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): DocumentCodec encode/decode is a legitimate binary serialization utility, not payload hiding. | ai | |
| provenance | publisher-changed | AI (provenance): Migration from dxos-bot to GitHub Actions CI is a normal pipeline change for this org. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/mesh/teleport/control_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| source-diff | obfuscated-file:dist/src/buf/proto/gen/dxos/bot_pb.js | AI (source-diff): Base64 protobuf file descriptors generated by @bufbuild/protoc-gen-es; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/src/buf/proto/gen/dxos/config_pb.js | AI (source-diff): Base64 protobuf file descriptors generated by @bufbuild/protoc-gen-es; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/src/buf/proto/gen/dxos/halo/credentials_pb.js | AI (source-diff): Base64 protobuf file descriptors generated by @bufbuild/protoc-gen-es; stable pattern for this package. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/mesh/teleport/admission-discovery_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/service/agentmanager_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/halo/credentials/auth_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/mesh/teleport/auth_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/mesh/teleport/automerge_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/echo/blob_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| source-diff | encoded-string-file:src/buf/proto/gen/dxos/mesh/teleport/blobsync_pb.ts | AI (source-diff): Base64 protobuf descriptor string; standard bufbuild codegen output. | ai | |
| phantom-deps | phantom-dep:@dxos/util | AI (phantom-deps): Same-org dep declared in package.json; phantom-dep heuristic false positive for this monorepo package. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 0.10.0 | 7 / 4 | |
| 0.9.0 | 7 / 4 | |
| 0.8.3 | 7 / 3 | |
| 0.8.1 | 7 / 3 | |
| 0.8.0 | 7 / 2 | |
| 0.7.4 | 7 / 2 | |
| 0.7.3 | 7 / 2 | |
| 0.7.2 | 7 / 2 | |
| 0.7.1 | 7 / 2 | |
| 0.7.0 | 7 / 2 | |
| 0.6.13 | 7 / 3 | |
| 0.6.12 | 7 / 3 | |
| 0.6.11 | 7 / 3 | |
| 0.6.10 | 7 / 3 | |
| 0.6.9 | 7 / 3 | |
| 0.6.8 | 7 / 3 | |
| 0.6.7 | 7 / 3 | |
| 0.6.6 | 7 / 3 | |
| 0.6.5 | 6 / 3 | |
| 0.6.4 | 6 / 3 | |
| 0.6.3 | 6 / 3 | |
| 0.6.2 | 6 / 1 | |
| 0.6.1 | 6 / 1 | |
| 0.6.0 | 6 / 1 | |
| 0.5.8 | 4 / 1 | |
| 0.5.7 | 4 / 1 | |
| 0.5.6 | 4 / 1 | |
| 0.5.5 | 4 / 1 | |
| 0.5.4 | 4 / 1 | |
| 0.5.3 | 4 / 1 | |
| 0.5.2 | 4 / 1 |
v0.10.0
4 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.1
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.4
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.3
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.2
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.1
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.13
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.12
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.11
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.10
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.9
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.8
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.7
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.6
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.