@enbox/agent
> **Research Preview** — Enbox is under active development. APIs may change without notice.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/browser.js | AI (source-diff): Bundled base64 helper code in esbuild output, not obfuscated payload. | ai | |
| source-diff | encoded-string-file:dist/browser.mjs | AI (source-diff): Bundled base64 helper code in esbuild output, not obfuscated payload. | ai | |
| provenance | missing-githead | AI (provenance): Metadata-only signal, no behavior change; consistent with normal monorepo publish flow. | ai | |
| phantom-deps | phantom-dep:interface-store | AI (phantom-deps): Used via config/plugin wiring, common false positive pattern. | ai | |
| phantom-deps | phantom-dep:ipfs-unixfs-exporter | AI (phantom-deps): Used via config/plugin wiring, common false positive pattern. | ai | |
| phantom-deps | phantom-dep:interface-blockstore | AI (phantom-deps): Used via config/plugin wiring, common false positive pattern. | ai | |
| dependencies | unvetted-dep:@enbox/connect | AI (dependencies): First-party sibling package in same monorepo/org, not a third-party unvetted dep. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Adds first-party @enbox/connect, not an axios-style supply-chain swap. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP appears only in JSDoc example comments (127.0.0.1 localhost), not in executable network calls. | ai | |
| phantom-deps | phantom-dep:ulidx | AI (phantom-deps): ulidx is listed in dependencies; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 51 of 78)
| Version | Deps | Published |
|---|---|---|
| 0.8.34 | 14 / 11 | |
| 0.8.33 | 14 / 11 | |
| 0.8.32 | 14 / 11 | |
| 0.8.31 | 14 / 11 | |
| 0.8.30 | 14 / 11 | |
| 0.8.29 | 14 / 11 | |
| 0.8.28 | 14 / 11 | |
| 0.8.27 | 14 / 11 | |
| 0.8.26 | 14 / 11 | |
| 0.8.25 | 14 / 11 | |
| 0.8.24 | 14 / 11 | |
| 0.8.23 | 14 / 11 | |
| 0.8.22 | 14 / 11 | |
| 0.8.20 | 14 / 11 | |
| 0.8.19 | 14 / 11 | |
| 0.8.18 | 14 / 11 | |
| 0.8.17 | 14 / 11 | |
| 0.8.16 | 14 / 11 | |
| 0.8.15 | 13 / 11 | |
| 0.8.14 | 13 / 11 | |
| 0.8.13 | 13 / 11 | |
| 0.8.12 | 13 / 11 | |
| 0.8.11 | 13 / 11 | |
| 0.8.10 | 13 / 11 | |
| 0.8.9 | 13 / 11 | |
| 0.8.8 | 11 / 13 | |
| 0.8.7 | 11 / 13 | |
| 0.8.6 | 11 / 13 | |
| 0.8.5 | 11 / 13 | |
| 0.8.4 | 11 / 13 | |
| 0.8.3 | 11 / 13 | |
| 0.8.2 | 11 / 13 | |
| 0.8.1 | 11 / 13 | |
| 0.8.0 | 11 / 13 | |
| 0.7.10 | 11 / 13 | |
| 0.7.9 | 11 / 13 | |
| 0.7.8 | 11 / 13 | |
| 0.7.7 | 11 / 13 | |
| 0.7.6 | 11 / 13 | |
| 0.7.5 | 11 / 13 | |
| 0.7.4 | 11 / 13 | |
| 0.7.3 | 11 / 13 | |
| 0.7.2 | 11 / 13 | |
| 0.7.1 | 11 / 13 | |
| 0.7.0 | 11 / 13 | |
| 0.6.8 | 11 / 13 | |
| 0.6.7 | 11 / 13 | |
| 0.6.6 | 11 / 13 | |
| 0.6.5 | 11 / 13 | |
| 0.6.4 | 11 / 13 | |
| 0.6.3 | 11 / 13 |
v0.8.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.