← Home

@effect/ai

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

schicklingmichael.arnaldieffect-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:hapi AI (typosquat): Scoped @effect/ai cannot typosquat unscoped short names; Levenshtein match is meaningless here. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Same rationale — scoped package, no plausible impersonation of 'pg'. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Same rationale — scoped package, no plausible impersonation of 'qs'. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Same rationale — scoped package, no plausible impersonation of 'joi'. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): Same rationale — scoped package, no plausible impersonation of 'ajv'. ai
bogus-package bogus-package AI (bogus-package): Established package with 110k weekly downloads; README style is a false positive for this library. ai

Versions (showing 51 of 189)

View all versions
Version Deps Published
0.37.0 1 / 0
0.36.0 1 / 0
0.35.0 1 / 0
0.34.0 1 / 0
0.33.2 1 / 0
0.33.1 1 / 0
0.33.0 1 / 0
0.32.1 1 / 0
0.32.0 1 / 0
0.31.1 1 / 0
0.31.0 1 / 0
0.30.0 1 / 0
0.29.1 1 / 0
0.29.0 1 / 0
0.28.4 1 / 0
0.28.3 1 / 0
0.28.2 1 / 0
0.28.1 1 / 0
0.28.0 1 / 0
0.27.1 1 / 0
0.27.0 1 / 0
0.26.1 1 / 0
0.26.0 1 / 0
0.25.2 1 / 0
0.25.1 1 / 0
0.25.0 1 / 0
0.24.0 1 / 0
0.23.0 1 / 0
0.22.2 1 / 0
0.22.1 1 / 0
0.22.0 1 / 0
0.21.17 1 / 0
0.21.16 1 / 0
0.21.15 1 / 0
0.21.14 1 / 0
0.21.13 1 / 0
0.21.12 1 / 0
0.21.11 1 / 0
0.21.10 1 / 0
0.21.9 1 / 0
0.21.8 1 / 0
0.21.7 1 / 0
0.21.6 1 / 0
0.21.5 1 / 0
0.21.4 1 / 0
0.21.3 1 / 0
0.21.2 1 / 0
0.21.1 1 / 0
0.21.0 1 / 0
0.20.0 1 / 0
0.19.4 1 / 0

v0.37.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.